CVEFinder.io

CVE-2026-34926

🔶 medium
🔍 Scan for this CVE
AI Summary

A directory traversal flaw in Trend Micro Apex One (on-premise) server allows an attacker with existing administrative OS credentials to inject malicious code for agent deployment. This actively exploited vulnerability requires local server access and prior compromise of the host operating system.

Summary

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.

CVSS Score
6.7
Medium
EPSS Score
12.7
Exploit Probability
Published Date
2026-05-21
First Seen: 2026-05-22
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 48.6% of all 338,292 vulnerabilities in our database.

#173,769
Below average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: May 22, 2026
🔍 Exploitation Status
Active
Exploits detected in the wild
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2026-07-23
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L
CWE IDs (Weakness Types)

📦 Affected Products 2

🔗 References 5

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2025-71210 ⛔ critical 9.8 3.8 A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an... 2026-05-21
CVE-2025-71211 ⛔ critical 9.8 3.8 A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an... 2026-05-21
CVE-2025-71212 ⚠️ high 7.8 0.5 A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileg... 2026-05-21
CVE-2025-71213 ⚠️ high 7.8 0.3 An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on ... 2026-05-21
CVE-2025-71214 ⚠️ high 7.8 0.4 An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attac... 2026-05-21
CVE-2025-71215 ⚠️ high 7.0 0.3 A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification c... 2026-05-21
These CVEs affect the same products