PT-2026-42465 · Trend Micro · Apex One
Trendai Incident Response (Ir) Team
·
Published
2026-05-21
·
Updated
2026-05-24
·
CVE-2026-34926
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Apex One (on-premise) (affected versions not specified)
Description
A directory traversal flaw in the on-premise version of the server allows a pre-authenticated local attacker to modify a key table. This action can be used to inject malicious code for deployment to agents on affected installations. Exploitation requires the attacker to have access to the server and have already obtained administrative credentials through other means. This issue has been exploited in the wild.
Recommendations
Apply the update released by Trend Micro to resolve this issue.
Fix
LPE
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apex One