Executive brief
Trend Micro Apex One is a centralized security management platform used to protect corporate endpoints. A vulnerability in the on-premise version allows an attacker who already has administrative access to the server to manipulate internal configuration files. This could lead to the deployment of malicious code to all connected computers (agents) across the organization, potentially resulting in a widespread compromise of the corporate network.
Technical details
A relative path traversal vulnerability (CWE-23) exists in the Trend Micro Apex One (on-premise) server component. To exploit this, an attacker must have local access to the server and have already obtained administrative credentials. The flaw allows the attacker to bypass directory restrictions to modify a key table on the server. Successful exploitation enables the injection of malicious code which is then distributed to and executed by the Apex One agents installed on managed endpoints. This vulnerability has reportedly been observed in the wild.
Affected products
- Trend Micro Apex One (On-Premise)
Timeline
- 2026-05-21: advisory: Initial disclosure by Trend Micro and NVD
- 2026-05-21: exploited: Reported as exploited in the wild at time of publication