← Back to advisories & guidance
May 22, 2026
JPCERT/CC
Alert
Summary
If these vulnerabilities are exploited, an authenticated attacker may be able to tamper with arbitrary files on the server, potentially allowing crafted code to be distributed to the security agent, or escalate privileges. Trend Micro Incorporated has reported that attacks exploiting the relative path traversal vulnerability in TrendAI Apex One(On Premise) (CVE-2026-34926) have been observed in the wild.Since one of the vulnerabilities has already been exploited in the wild, the users of the affected products are recommended to update the affected system to the latest version as soon as possible.Please refer to the information provided by Trend Micro. ITW SECURITY BULLETIN: Apex One and Vision One - Standard Endpoint Protection (SEP) May 2026 Security Bulletin Affected products are as follows: According to Trend Micro, the only product that could be vulnerable to the exploitation of the relative path traversal vulnerability(CVE-2026-34926) is TrendAI Apex One (On Premise). Please consider applying the appropriate patch according to the information provided by Trend Micro. Trend Micro has released the patches listed below that address the vulnerabilities.
News Coverage
Articles from the monitored vendor research blogs and security news feeds that
reference a CVE cited in this publication, or name the campaign it covers.
Coverage begins when feed monitoring started; earlier articles are not indexed.
CVEs Referenced in This Publication
Extracted from the publication text. Each CVE links to its tracked detail page.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.