Junglewise Threat Intelligence

CVE-2026-34927: Trend Micro Apex One and Vision One SEP origin validation privilege escalation

CVE-2026-34927 · Severity: high · CVSS 7.8 · Published 2026-05-21

Technologies: Trend Micro Vision One Endpoint Security Agent, Trend Micro Apex One Agent, Trend Micro Apex One as a Service Agent. Vendors: Trend Micro.

Executive brief

Trend Micro Apex One and Vision One endpoint agents are security software used to protect corporate laptops and servers from malware. A vulnerability in these agents could allow a user who already has limited access to a computer to gain full administrative control. This could be used by an attacker to disable security protections or steal sensitive data from the affected machine.

Technical details

An origin validation error (CWE-346) exists in the Trend Micro Apex One and Vision One Standard Endpoint Protection (SEP) agents. The vulnerability stems from insufficient verification of the source of inter-process communications or requests. To exploit this, an attacker must first have the ability to execute low-privileged code on the target Windows system. Successful exploitation allows the attacker to bypass security boundaries and escalate privileges to a higher level, potentially SYSTEM. Trend Micro has released patches for both on-premises and SaaS versions of the affected products to address this issue.

Affected products

  • Trend Micro Apex One (On-prem) Agent Below 17079
  • Trend Micro Apex One as a Service Agent Below 14.0.20731
  • Trend Micro Vision One Endpoint Security - Standard Endpoint Protection (SEP) Agent Below 14.0.20731

Timeline

  • 2026-05-21: disclosed
  • 2026-05-21: advisory
  • 2026-05-21: patched

References

Related threats