• News/
  • bleepingcomputer-20260522133919

Trend Micro warns of Apex One zero-day exploited in the wild

BleepingComputer
·
Sergiu Gatlan
·
Published May 22, 2026
·
Updated

Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. Apex One is Trend Micro's enterprise-grade endpoint security platform that protects corporate networks from a wide range of security threats, including malware, ransomware, fileless attacks, and web-based threats. Tracked as CVE-2026-34926, this directory traversal vulnerability in the Apex One (on-premises) server allows local attackers with admin privileges to inject malicious code. "A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations," Trend Micro saidon Thursday. "This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability." However, despite the restrictive requirements for successful exploitation, the company warned that "TrendAI has observed at least one attempt to exploit this vulnerability in the wild." Yesterday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added CVE-2026-34926 to its list of actively exploited vulnerabilities and ordered federal agencies to patch their devices by June 4. "These types of vulnerabilities are frequent...

Read full article

Affected Software

3 affected components
Trend Micro Apex One (on-premise) server
Trend Micro Apex One Standard Endpoint Protection (SEP) agent
Trend Micro Apex One
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability in Trend Micro's Apex One security software that is being actively exploited in the wild.

2

What security implications are discussed in the article?

The article highlights the risks associated with the exploitation of the Apex One zero-day vulnerability on Windows systems.

3

What products are affected by this vulnerability?

The affected products include Trend Micro Apex One on-premise server and Trend Micro Apex One Standard Endpoint Protection (SEP) agent.

4

Who has reported the vulnerability?

The vulnerability has been reported by Trend Micro, the Japanese cybersecurity software company.

5

What type of attacks are being targeted by this exploit?

The exploit is targeting corporate networks through attacks aimed at Windows systems using Apex One.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203