
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34930 is a local privilege escalation vulnerability (Origin Validation Error) in the Trend Micro Apex One and Vision One Standard Endpoint Protection (SEP) Security Agent, specifically within a process protection mechanism of the Apex One NT Listener service. Discovered and disclosed on May 21, 2026, it affects Apex One on-premises agent builds below 14.0.0.17079 and Apex One as a Service / Vision One SEP SaaS agent builds below 14.0.20731, both on Windows. It is one of several related CVEs (CVE-2026-34927 through CVE-2026-34930) reported by researcher Lays (@_L4ys) of TRAPA Security via the Zero Day Initiative. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Trend Micro Advisory, GitHub Advisory).
The root cause is classified as CWE-346 (Origin Validation Error): the Apex One/SEP Security Agent's process protection mechanism fails to sufficiently validate the origin of commands it receives, allowing a local attacker to send crafted commands that are accepted as legitimate. This is analogous to CVE-2026-34927, CVE-2026-34928, and CVE-2026-34929, which exploit similar origin validation flaws in different IPC mechanisms (named pipes, inter-process communication, and process protection), with CVE-2026-34930 specifically targeting a distinct process protection mechanism (ZDI-CAN-28089). Exploitation requires the attacker to already have low-privileged code execution on the target Windows system; no network access or user interaction is needed beyond that initial foothold (Trend Micro Advisory, ZDI Advisory).
Successful exploitation allows a local attacker with low privileges to escalate to SYSTEM-level privileges and execute arbitrary code in the context of the SYSTEM account on the affected Windows endpoint. This grants full control over the compromised host, including access to all data, the ability to disable security controls, install persistent backdoors, and potentially pivot to other systems on the network. Confidentiality, integrity, and availability are all rated as High impact (Trend Micro Advisory, GitHub Advisory).
sc query or process enumeration).cmd.exe, powershell.exe, or other shells).Trend Micro has released patches addressing CVE-2026-34930 and related vulnerabilities. For Apex One on-premises, update to SP1 CP Build 18012 (for existing SP1 users) or SP1 Build 17079 (for new installs), ensuring the agent is at least build 14.0.0.17079. For Apex One as a Service and Vision One SEP, update the Security Agent to build 14.0.20731 or later. As a general mitigating factor, restrict local user access to affected systems and review remote access policies. Trend Micro strongly encourages immediate patching, especially given active exploitation of a related vulnerability (CVE-2026-34926) in the same bulletin (Trend Micro Advisory).
The Belgium Centre for Cybersecurity (CCB) issued a warning regarding multiple vulnerabilities in TrendAI Apex One and Vision One SEP, including CVE-2026-34930, noting active exploitation concerns in the broader bulletin (CCB Advisory). Japan's JVN and JVNDB also published advisories covering the vulnerability cluster. The Zero Day Initiative published advisory ZDI-26-323 covering CVE-2026-34930, credited to researcher Lays (@_L4ys) of TRAPA Security (ZDI Advisory). Community discussion has been limited, with no significant social media controversy, though the bulletin's ITW exploitation notice for CVE-2026-34926 has drawn attention to the entire vulnerability set.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."