Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. Apex One is Trend Micro's enterprise-grade endpoint security platform that protects corporate networks from a wide range of security threats, including malware, ransomware, fileless attacks, and web-based threats. Tracked as CVE-2026-34926, this directory traversal vulnerability in the Apex One (on-premises) server allows local attackers with admin privileges to inject malicious code. "A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations," Trend Micro saidon Thursday. "This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability." However, despite the restrictive requirements for successful exploitation, the company warned that "TrendAI has observed at least one attempt to exploit this vulnerability in the wild." Yesterday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added CVE-2026-34926 to its list of actively exploited vulnerabilities and ordered federal agencies to patch their devices by June 4. "These types of vulnerabilities are frequent...
Trend Micro warns of Apex One zero-day exploited in the wild
BleepingComputer
·Sergiu Gatlan
·Published May 22, 2026
·Updated
Affected Software
3 affected components
Trend Micro Apex One (on-premise) server
Trend Micro Apex One Standard Endpoint Protection (SEP) agent
Trend Micro Apex One
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day vulnerability in Trend Micro's Apex One security software that is being actively exploited in the wild.
2
What security implications are discussed in the article?
The article highlights the risks associated with the exploitation of the Apex One zero-day vulnerability on Windows systems.
3
What products are affected by this vulnerability?
The affected products include Trend Micro Apex One on-premise server and Trend Micro Apex One Standard Endpoint Protection (SEP) agent.
4
Who has reported the vulnerability?
The vulnerability has been reported by Trend Micro, the Japanese cybersecurity software company.
5
What type of attacks are being targeted by this exploit?
The exploit is targeting corporate networks through attacks aimed at Windows systems using Apex One.