Knox CVE Database
/
CVE-2026-34926
Medium
6.7

CVE-2026-34926: Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

Added to the CISA KEV catalog:
May 21, 2026

Overview

Trend Micro Apex One (on-premise) contains a relative path traversal flaw in its server component that allows an attacker with local access and administrative credentials to escape the intended directory, modify a key table on the server, and push attacker-controlled code to every managed security agent in the deployment. Exploitation requires prior acquisition of administrative credentials through a separate method. Trend Micro has confirmed at least one in-the-wild exploitation attempt, and the vulnerability affects on-premise installations only.

Vulnerability details

Affected vendor
Trend Micro
Affected product
Apex One
Weakness type (CWE)
CWE-23

Relative path traversal (CWE-23) occurs when an application accepts user-supplied path components without stripping or rejecting sequences such as "../" that escape the intended directory boundary. In the Apex One on-premise server, the flaw allows a crafted path to reach and modify a key table that governs what code the server distributes to its managed security agents. Because the server acts as a trusted distribution authority for the entire agent fleet, a write to that table has consequences well beyond the server itself.


An attacker who has already obtained administrative credentials to the Apex One server submits a crafted traversal path that writes attacker-controlled content into the key table. The server then distributes that content to managed security agents as a legitimate update, achieving code execution across the agent fleet. Exploitation is constrained to local access on the on-premise server and requires administrative credentials obtained through a prior, separate compromise. Trend Micro has confirmed at least one exploitation attempt in the wild, making this a credible, active threat for organizations running on-premise deployments.

Severity and impact

6.7
Medium
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L
Attack vector
Local
Attack complexity
High
Privileges required
High
User interaction
None
Scope
Changed
Confidentiality impact
High
Integrity impact
Low
Availability impact
Low

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Audit Apex One server-side file-system activity for writes to key table files from processes or sessions that include path components containing traversal sequences ("../" or URL-encoded equivalents), particularly outside expected administrative maintenance windows.
  • Review Apex One server audit logs for administrative authentication events followed immediately by unusual file-modification activity or agent policy/update-package changes not initiated through the standard management console workflow.
  • Monitor managed security agents for unexpected software deployments or configuration changes that do not correspond to an authorized change-management record, which may indicate the key table has been tampered with upstream.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
June 4, 2026

Additional hardening

  • Upgrade Apex One on-premise server and agent to build 14.0.0.17079 (or the SP1 Critical Patch build 18012 for existing SP1 users); upgrade Apex One as a Service security agents to build 14.0.20731. See References for the vendor bulletin.
  • Restrict administrative access to the Apex One server to a dedicated jump host or privileged-access workstation, and require multi-factor authentication for all administrative accounts, reducing the likelihood that credentials can be obtained through a prior compromise.
  • Apply least-privilege controls to the Apex One server's file system so that only the specific service accounts that require write access to key table directories hold that permission, limiting the blast radius of a traversal exploit.
  • Audit and rotate all administrative credentials for the Apex One server immediately, particularly if any prior unauthorized access or credential exposure is suspected, given confirmed in-the-wild exploitation of this flaw.

Key dates

Published (NVD)
May 21, 2026
Added to CISA KEV
May 21, 2026
Remediation deadline
June 4, 2026
Last updated
July 23, 2026

References

Frequently asked questions

Does CVE-2026-34926 affect my FedRAMP authorization?

If Trend Micro Apex One runs inside your authorization boundary, yes. CVE-2026-34926 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of June 4, 2026 has already passed. An unpatched KEV inside a FedRAMP boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency now. Remediate it or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-34926?

Knox does not patch your software. Remediating Trend Micro Apex One is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; managing your compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-34926 surfaces, exposure appears through ongoing monitoring rather than waiting until an assessor flags it at review time. That earlier signal gives your team more time to act.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-34926's remediation deadline of June 4, 2026 has passed. What happens now?

If CVE-2026-34926 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the finding and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship in good standing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.