CISA has added a zero-day affecting Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, reflecting that the flaw is being exploited in real-world attacks. Multiple reports identify the issue as a relative directory path traversal vulnerability labeled CVE-2026-34926. Trend Micro confirms that its TrendAI threat monitoring has observed at least one attempt to exploit the vulnerability “in the wild.” The company attributes discovery and reporting of the activity to its TrendAI enterprise cybersecurity incident response team. The vulnerability affects the Trend Micro Apex One platform, a security product used to protect devices across an organization. While the sources emphasize active exploitation and the presence of the vulnerability in CISA’s KEV list, they do not provide additional technical details about exploitation beyond describing it as a path traversal issue. The overall message across outlets is that organizations using Apex One should treat the vulnerability as actively exploited and take mitigation steps consistent with vendor and CISA guidance.
CISA Warns of Exploited Zero-Day in Trend Micro Apex One (CVE-2026-34926)
CISA has added a zero-day affecting Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, reflecting that the flaw is being exploited in real-world attacks. Multiple reports ident...
- CISA adds CVE-2026-34926 to its KEV (Known Exploited Vulnerabilities) list.
- The affected product is Trend Micro Apex One.
- The vulnerability is described as a relative directory path traversal flaw.
- Trend Micro reports observing attempts to exploit the vulnerability in the wild.
- The reports identify Trend Micro’s TrendAI incident response team as involved in detecting/reporting the activity.
A relative directory path traversal vulnerability (CVE-2026-34926) in Trend Micro’s Apex One platform has been exploited in zero-day attacks, the company confirmed. “TrendAI has observed at least one attempt to exploit this vulnerability in the wild,” Trend Micro noted, and credited the incident response team of its TrendAI enterprise cybersecurity business for reporting it. About Trend Micro Apex One Trend Micro Apex One is a security platform that protects all the devices in an organization … More → The post Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926) appeared first on Help Net Security.
2 months agoCISA has already added the flaw to its KEV database.
3 months agoMeta and U.S. states discuss possible settlement over teen social media harm, Bloomberg reports
Meta is in discussions with multiple U.S. states about a potential settlement related to alleged harm from social media...
Developers describe new AI agent workflows for coding, reviews, and automation
Multiple Dev.to posts and related reporting describe how software work is shifting as AI coding agents become more capab...
Zoom issues broadly expected outlook despite expanding its product lineup
Zoom Communications reports a sales outlook for the current quarter that is broadly in line with analysts’ expectations,...