Multiple Vulnerabilities in TrendAI Apex One Security Agent Allow Local Privilege Escalation
Article Content
Three vulnerabilities have been identified in TrendAI Apex One Security Agent, allowing local attackers to escalate privileges. The first two vulnerabilities (ZDI-26-652 and ZDI-26-653) are related to a flaw in the cache mechanism due to improper cache key checking during signature verification. The third vulnerability (ZDI-26-654) involves incomplete cleanup in the TmccCore component, leading to privilege escalation. Attackers must have low-privileged access to exploit these vulnerabilities. TrendAI has issued updates to address these issues. The vulnerabilities were reported to the vendor between October 2025 and January 2026, with public advisories released on September 10, 2026.
Key Points: • Three vulnerabilities in TrendAI Apex One allow local privilege escalation. • Attackers need low-privileged access to exploit these vulnerabilities. • TrendAI has released updates to mitigate these security issues.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.