Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2026-34926

CVSS 6.7 · Medium KEV EPSS 0.19% · P41

Affected Version Matrix 2

VendorProductVersion RangeStatus
Trend Micro, Inc.TrendAI Apex One2019 (14.0)< 14.0.0.17079affected
Trend Micro, Inc.TrendAI Apex One as a ServiceSaaS< 14.0.20731affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-34926

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
相对路径遍历
Source: NVD (National Vulnerability Database)
Vulnerability Title
TrendAI Apex One 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
TrendAI Apex One是TrendAI公司的一个提供终端防护、恶意软件检测与威胁响应能力的企业安全平台。 TrendAI Apex One存在安全漏洞,该漏洞源于目录遍历,可能导致预先认证的本地攻击者修改服务器上的关键表以注入恶意代码部署到代理。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Trend Micro, Inc.TrendAI Apex One 2019 (14.0) ~ 14.0.0.17079 cpe:2.3:a:trendmicro:apexone_op:14.0.0.17079:*:*:*:*:*:*:*
Trend Micro, Inc.TrendAI Apex One as a Service SaaS ~ 14.0.20731 cpe:2.3:a:trendmicro:apexone_saas:14.0.0.20731:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-34926

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-34926

登录查看更多情报信息。

Vendor Advisories for CVE-2026-34926 (4)

Same Patch Batch · Trend Micro, Inc. · 2026-05-21 · 16 CVEs total

CVE-2025-712119.8 CRITICALTrend Micro Apex One 路径遍历漏洞
CVE-2025-712109.8 CRITICALTrend Micro Apex One 路径遍历漏洞
CVE-2026-452077.8 HIGHTrend Micro Apex One和TrendAI Vision One Endpoint Security - Standard Endpoint Protection 访
CVE-2026-452087.8 HIGHTrend Micro Apex One和TrendAI Vision One Endpoint Security - Standard Endpoint Protection 安
CVE-2026-452067.8 HIGHTrend Micro TrendAI Vision One Endpoint Security - Standard Endpoint Protection 访问控制错误漏洞
CVE-2026-349287.8 HIGHTrend Micro Apex One和TrendAI Vision One Endpoint Security - Standard Endpoint Protection 访
CVE-2026-349277.8 HIGHTrend Micro Apex One和TrendAI Vision One Endpoint Security - Standard Endpoint Protection 访
CVE-2026-349297.8 HIGHTrend Micro Apex One和TrendAI Vision One Endpoint Security - Standard Endpoint Protection 访
CVE-2026-349307.8 HIGHTrend Micro Apex One和TrendAI Vision One Endpoint Security - Standard Endpoint Protection 访
CVE-2025-712127.8 HIGHTrend Micro Apex One 后置链接漏洞
CVE-2025-712137.8 HIGHTrend Micro Apex One 访问控制错误漏洞
CVE-2025-71217Trend Micro Apex One 访问控制错误漏洞
CVE-2025-71216Trend Micro Apex One 安全漏洞
CVE-2025-71214Trend Micro Apex One 访问控制错误漏洞
CVE-2025-71215Trend Micro Apex One 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-34926

No comments yet


Leave a comment