This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 24 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal Vulnerability Allows Local Admin to Deploy Malicious Code on Trend Micro Apex One On-Premises |
Wed, 24 Jun 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal Vulnerability Allows Local Admin to Deploy Malicious Code on Trend Micro Apex One On-Premises |
Wed, 24 Jun 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal Enables Local Admin to Alter Key Table for Agent Code Deployment |
Tue, 23 Jun 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal Enables Local Admin to Alter Key Table for Agent Code Deployment |
Tue, 23 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal Enables Local Key Table Manipulation in Trend Micro Apex One |
Tue, 23 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal Enables Local Key Table Manipulation in Trend Micro Apex One |
Tue, 26 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Trendmicro apex One
|
|
| CPEs | cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:* cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:* |
|
| Vendors & Products |
Trendmicro apex One
|
Fri, 22 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Thu, 21 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal in Trend Micro Apex One Server Enabling Local Code Deployment |
Thu, 21 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
ssvc
|
Thu, 21 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Thu, 21 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal in Trend Micro Apex One Server Enabling Local Code Deployment |
Thu, 21 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability. | |
| First Time appeared |
Trendmicro
Trendmicro apexone Op Trendmicro apexone Saas |
|
| Weaknesses | CWE-23 | |
| CPEs | cpe:2.3:a:trendmicro:apexone_op:14.0.0.17079:*:*:*:*:*:*:* cpe:2.3:a:trendmicro:apexone_saas:14.0.0.20731:*:*:*:*:*:*:* |
|
| Vendors & Products |
Trendmicro
Trendmicro apexone Op Trendmicro apexone Saas |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: trendmicro
Published:
Updated: 2026-05-22T12:47:07.213Z
Reserved: 2026-03-31T17:22:13.504Z
Link: CVE-2026-34926
Updated: 2026-05-21T13:50:37.989Z
Status : Analyzed
Published: 2026-05-21T14:16:45.213
Modified: 2026-06-17T10:39:49.727
Link: CVE-2026-34926
No data.
OpenCVE Enrichment
Updated: 2026-06-24T13:30:06Z