CVE detail
CVE-2026-34926
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
- Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flawHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Coinflow CISO on crypto payments security under AI pressure Crypto payment firms sit near the top of the target list for advanced persistent threat groups, and the workload on their security leaders keeps growing. Malcolm Portelli, CISO at Coinflow, runs the company’s security program from Malta. Coinflow is headquartered in the United States and operates across multiple jurisdictions. Portelli sat … More →
newswww.helpnetsecurity.comMay 31, 2026, 8:00 AM A relative directory path traversal vulnerability (CVE-2026-34926) in Trend Micro’s Apex One platform has been exploited in zero-day attacks, the company confirmed. “TrendAI has observed at least one attempt to exploit this vulnerability in the wild,” Trend Micro noted, and credited the incident response team of its TrendAI enterprise cybersecurity business for reporting it. About Trend Micro Apex One Trend Micro Apex One is a security platform that protects all the devices in an organization … More →
newswww.helpnetsecurity.comMay 26, 2026, 1:48 PM- 25th May – Threat Intelligence ReportCheck Point Research
eys, cracked WordPress accounts, and drained a crypto wallet. VULNERABILITIES AND PATCHES Microsoft published fixes for CVE-2026-41091 and CVE-2026-45498, two actively exploited Windows Defender flaws affecting the Malware Protection Engine and Defender Antimalware Platform. The first allows local privilege escalation, while the second can cause denial
vendorresearch.checkpoint.comMay 25, 2026, 3:08 PM - U.S. CISA adds Trend Micro Apex One and Langflow to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Trend Micro Apex One and Langflow flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: CVE-2025-34291 (CVSS score of 9.4) is […]
newssecurityaffairs.comMay 22, 2026, 9:13 AM CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One.
newswww.securityweek.comMay 22, 2026, 8:19 AMNo excerpt available.
Mitigationwww.cisa.govMay 21, 2026, 2:16 PM- https://www.jpcert.or.jp/english/at/2026/at260014.htmlwww.jpcert.or.jp
No excerpt available.
Third Party Advisorywww.jpcert.or.jpMay 21, 2026, 2:16 PM - https://success.trendmicro.com/ja-JP/solution/KA-0022974success.trendmicro.com
No excerpt available.
Vendor Advisorysuccess.trendmicro.comMay 21, 2026, 2:16 PM - https://success.trendmicro.com/en-US/solution/KA-0023430success.trendmicro.com
No excerpt available.
Vendor Advisorysuccess.trendmicro.comMay 21, 2026, 2:16 PM No excerpt available.
Third Party Advisoryjvn.jpMay 21, 2026, 2:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-18192CVSS 7.1 · High
VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system…
- CVE-2026-63303CVSS 5.1 · Medium
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolv…
- CVE-2026-47078CVSS 4.8 · Medium
Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted zip archive. zip:unzip/1,2 an…
- CVE-2026-15802CVSS 8.1 · High
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in…
- CVE-2026-58481CVSS 6.5 · Medium
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its pat…
- CVE-2026-58413CVSS 6.1 · Medium
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup path with `join(envDir, '.bac…