logo

Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926)

ID: d415c2af-2f6c-5e06-9ef5-549839d4d870

STIX ID: report--d415c2af-2f6c-5e06-9ef5-549839d4d870

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Zeljka Zorz

...
...

Trend Micro confirmed that CVE-2026-34926, a relative directory path traversal affecting Apex One on-premises servers, has been observed exploited in the wild; an attacker with prior access and administrative credentials can modify server tables to inject malicious code and distribute it to agents. Trend Micro urges immediate patching and access reviews, and CISA has added the CVE to its Known Exploited Vulnerabilities catalog with mandated patching timelines for federal agencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.