CVSS v3
6.7
MEDIUM
EPSS Score
0.3%
exploit probability
CISA KEV
Yes
known exploited
Exploitation
—
SSVC status
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
Yes. CVE-2026-34926 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 6/4/2026.
CVE-2026-34926 has a CVSS v3 base score of 6.7 (MEDIUM severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.