CISA has added a zero-day affecting Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, reflecting that the flaw is being exploited in real-world attacks. Multiple reports identify the issue as a relative directory path traversal vulnerability labeled CVE-2026-34926. Trend Micro confirms that its TrendAI threat monitoring has observed at least one attempt to exploit the vulnerability “in the wild.” The company attributes discovery and reporting of the activity to its TrendAI enterprise cybersecurity incident response team. The vulnerability affects the Trend Micro Apex One platform, a security product used to protect devices across an organization. While the sources emphasize active exploitation and the presence of the vulnerability in CISA’s KEV list, they do not provide additional technical details about exploitation beyond describing it as a path traversal issue. The overall message across outlets is that organizations using Apex One should treat the vulnerability as actively exploited and take mitigation steps consistent with vendor and CISA guidance.