---
schema: 1
kind: vulnerability
title: "CVE-2026-34926 — Trend Micro Apex One On-Premise: post-auth directory traversal by admin-credential holder injects code deployed fleet-wide to all managed agents (CISA KEV, ITW)"
headline: "CVE-2026-34926 — Trend Micro Apex One On-Premise: post-auth directory traversal by admin-credential holder injects code deployed fleet-wide to all managed"
summary: "CISA KEV: Trend Micro Apex One On-Premise directory traversal (CVE-2026-34926) actively exploited — management server compromise injects malicious code propagated fleet-wide to all managed agents via built-in update mechanism; JPCERT confirmed ITW exploitation 2026-05-21; patch to build 17079 required (CISA KEV, 2026-05-21)."
discovered_at: "2026-05-22T05:00:03Z"
event_date: null
run_id: 2026-05-22-5b90d5a1
priority: critical
immediate_action:
  title: Patch Trend Micro Apex One On-Premise management server to build 17079
  action: "JPCERT/CC confirmed on 2026-05-21 that CVE-2026-34926 (CISA KEV, added 2026-05-21) is being actively exploited in the wild: an authenticated attacker with administrative access to the Apex One management server traverses the server's directory structure to modify a key table and inject malicious code that Apex One's own update mechanism then deploys to every managed agent in the fleet — one compromised management console equals fleet-wide code execution. Admin credentials to the Apex One server are the entry prerequisite; attackers obtain them via phishing, credential theft, or brute force."
tags:
  - vulnerabilities
  - actively-exploited
  - cisa-kev
  - patch-available
regions:
  - global
sectors: []
entities: []
cves:
  - id: CVE-2026-34926
    cvss: "6.7"
    epss: null
    type: null
    vector: local
    auth: post-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://www.cisa.gov/news-events/alerts/2026/05/21/cisa-adds-two-known-exploited-vulnerabilities-catalog"
    publisher: "CISA KEV alert, 2026-05-21"
    role: primary
  - url: "https://www.jpcert.or.jp/english/at/2026/at260014.html"
    publisher: "JPCERT/CC at260014, 2026-05-22"
    role: corroborating
  - url: "https://success.trendmicro.com/en-US/solution/KA-0023430"
    publisher: Trend Micro KA-0023430
    role: corroborating
closed_sources: []
evidence:
  - quote: Trend Micro Incorporated has reported that attacks exploiting the relative path traversal vulnerability in TrendAI Apex One(On Premise) (CVE-2026-34926) have been observed in the wild.
    publisher: JPCERT/CC
  - quote: a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
    publisher: HKCERT
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Patch Trend Micro Apex One On-Premise to server/agent build 17079** — CVE-2026-34926 is actively exploited ITW (JPCERT, 2026-05-22); a compromised management console deploys attacker code to all managed endpoints. Verify version via Apex One management console's product version page; apply [KA-0023430](https://success.trendmicro.com/en-US/solution/KA-0023430). Treat the Apex One server host as Tier-0 — restrict management VLAN access before patch is applied."
migrated_from: briefs/2026-05-22.md
---

CVE-2026-34926 (CVSS 6.7, CWE-23 Relative Path Traversal) affects Apex One On-Premise server and agent builds below 17079. An authenticated attacker who has already obtained administrative credentials to the Apex One management server traverses the directory structure to modify a key table, injecting malicious code that the management server then distributes to all enrolled agent endpoints via the product's built-in update mechanism — one compromised management console results in fleet-wide code execution on every managed endpoint. The exploitation prerequisite (admin credentials to the Apex One server) does not reduce urgency: CISA added CVE-2026-34926 to KEV on 2026-05-21 following confirmed ITW exploitation, and management server admin accounts are a high-value target for credential theft campaigns. JPCERT/CC confirmed exploitation in the wild on 2026-05-22; CISA added CVE-2026-34926 to KEV on 2026-05-21. Fixed: server and agent build 17079 per [Trend Micro KA-0023430](https://success.trendmicro.com/en-US/solution/KA-0023430). The Apex One as a Service (SaaS) variant is not affected. Until patched, restrict local-network access to the Apex One management console to a dedicated management VLAN; treat the console host as Tier-0 infrastructure given its fleet-wide code distribution capability. Technique: `T1574 Hijack Execution Flow` via trusted software update path.
