ThreatCluster

Multiple Vulnerabilities in TrendAI Apex One Security Agent Allow Local Privilege Escalation

First seen 10 Sep 2026, 13:46 UTC Zerodayinitiativewww.cve.org 57

Article Content

Browse articles
ThreatCluster

Three vulnerabilities have been identified in TrendAI Apex One Security Agent, allowing local attackers to escalate privileges. The first two vulnerabilities (ZDI-26-652 and ZDI-26-653) are related to a flaw in the cache mechanism due to improper cache key checking during signature verification. The third vulnerability (ZDI-26-654) involves incomplete cleanup in the TmccCore component, leading to privilege escalation. Attackers must have low-privileged access to exploit these vulnerabilities. TrendAI has issued updates to address these issues. The vulnerabilities were reported to the vendor between October 2025 and January 2026, with public advisories released on September 10, 2026.

Key Points: • Three vulnerabilities in TrendAI Apex One allow local privilege escalation. • Attackers need low-privileged access to exploit these vulnerabilities. • TrendAI has released updates to mitigate these security issues.

Ask AI about this cluster

Timeline

2025-10-08
Vulnerability ZDI-26-654 reported
TrendAI was alerted to the incomplete cleanup issue in the TmccCore component.
Article 3
2025-10-29
Vulnerability ZDI-26-653 reported
TrendAI was notified about the cache mechanism flaw allowing privilege escalation.
Article 2
2026-01-08
Vulnerability ZDI-26-652 reported
TrendAI was informed about the cache mechanism flaw related to signature verification.
Article 1
2026-09-10
Public advisory released for all vulnerabilities
TrendAI coordinated the public release of advisories for the identified vulnerabilities.
Article 1
2026-09-10
Advisories updated
TrendAI updated the advisories to reflect the latest information on the vulnerabilities.
Article 1