Answer in brief
CVE-2026-34926 records a High severity vulnerability in CISA ADP Vulnrichment. The current sources mark it as known exploited. The current feed maps Trend Micro, Inc./TrendAI Apex One (generic), Trend Micro, Inc./TrendAI Apex One as a Service (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Trend Micro, Inc./TrendAI Apex One (generic), Trend Micro, Inc./TrendAI Apex One as a Service (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Trend Micro, Inc./TrendAI Apex Onegeneric | >=2019 (14.0) <14.0.0.17079 | 14.0.0.17079 |
| Trend Micro, Inc./TrendAI Apex One as a Servicegeneric | >=SaaS <14.0.20731 | 14.0.20731 |
Published upstream
May 21, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
May 21, 2026
Evidence: source:kev:kev:kev:recordA directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-34926 records a High severity vulnerability in CISA ADP Vulnrichment. The current sources mark it as known exploited. The current feed maps Trend Micro, Inc./TrendAI Apex One (generic), Trend Micro, Inc./TrendAI Apex One as a Service (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Trend Micro, Inc./TrendAI Apex One (generic), Trend Micro, Inc./TrendAI Apex One as a Service (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Trend Micro, Inc./TrendAI Apex Onegeneric | >=2019 (14.0) <14.0.0.17079 | 14.0.0.17079 |
| Trend Micro, Inc./TrendAI Apex One as a Servicegeneric | >=SaaS <14.0.20731 | 14.0.20731 |
Published upstream
May 21, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
May 21, 2026
Evidence: source:kev:kev:kev:recordA directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
Quoted source text, attributed separately from HOL analysis.