TrendAI Patches Apex One Zero-Day Exploited in the Wild

https://www.securityweek.com/wp-content/uploads/2025/08/Trend-Micro.jpeg

Vulnerabilities

CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One.

TrendAI, Trend Micro’s enterprise business, has informed customers that it has patched another Apex One vulnerability that has been exploited in the wild.

The zero-day, tracked as CVE-2026-34926, is a medium-severity directory traversal issue that can be exploited by an unauthenticated local attacker to “modify a key table on the server to inject malicious code to deploy to agents on affected installations”.

TrendAI noted that the attacker requires admin credentials to the server, and the attack only works against the on-premises version of Apex One.

No information has been shared by the cybersecurity firm on the attacks exploiting the latest zero-day. The vulnerability was discovered internally by TrendAI’s incident response team.

It’s not uncommon for threat actors to exploit vulnerabilitiesin Apex products, but attribution information is rarely made public. Some...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE