Lyrie
Actively Exploited
CVSS 6.7ACTIVELY EXPLOITED4 sources verified·1 min read
By Lyrie Threat Intelligence·5/21/2026

MEDIUM: CVE-2026-34926 actively exploited — multiple vendors

CVE: CVE-2026-34926

CVSS: 6.7 (3.1) — CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L

Severity: MEDIUM

Status: ✅ Confirmed exploited in the wild (CISA KEV)

Affected

_See vendor advisory_

Summary

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.

Verified Sources

References

  • https://jvn.jp/en/vu/JVNVU90583059/
  • https://success.trendmicro.com/en-US/solution/KA-0023430
  • https://success.trendmicro.com/ja-JP/solution/KA-0022974
  • https://www.jpcert.or.jp/english/at/2026/at260014.html

_Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation._

Lyrie Verdict

Lyrie's autonomous detection layer catches active exploitation primitives at machine speed — closing the gap between disclosure and weaponization that traditional defense simply can't cover.

Validated sources

  1. [1]NVD
  2. [2]GitHub Advisory
  3. [3]MITRE
  4. [4]CISA KEV