Endpoint security (EDR and XDR)

Trellix advisories: every record the registers tie to its products

In one line

52 advisories are attributed to Trellix products in this record, covering October 2022 to July 2026, and none of them appears in the CISA catalogue of known exploited vulnerabilities. A further 0 register entries mention Trellix without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.

Attributed

52

tied to a named product

Known exploited

0

in the CISA catalogue

Rated critical

1

by the register

Last checked

Jul 17, 2026

sources re-queried

Why this list is shorter than a CVE mirror

The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Trellix, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.

0 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.

50 of the 52 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.

The full list, most recently exploited and most recent first

Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.

  • CVE-2026-12588mediumCVSS 6.0Jul 14, 2026

    An attacker with access to an HX 10.0.0  and previous versions, may send specially-crafted data to the HX console.

  • CVE-2025-7958highCVSS 7.1Jun 26, 2026

    A Code Injection vulnerability existed in Trellix Network Security CM and NX.

  • WID-SEC-2026-0538mediumCVSS 6.4Feb 26, 2026

    Affected products: Trellix Endpoint Security

  • CVE-2025-14963mediumCVSS 6.2Feb 24, 2026

    A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges.

  • WID-SEC-2025-2597highCVSS 8.8Nov 14, 2025

    Affected products: Trellix Agent

  • WID-SEC-2025-1609lowCVSS 4.4Oct 01, 2025

    Affected products: Trellix Endpoint Security, Absolute Secure Access

  • CVE-2025-0664mediumCVSS 6.7Jul 21, 2025

    A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent to load an arbitrary local library.

  • WID-SEC-2025-1429mediumCVSS 5.6Jul 01, 2025

    Affected products: Trellix Endpoint Security

  • CVE-2025-5967mediumCVSS 5.3Jul 01, 2025

    A stored cross-site scripting vulnerability in ENS HX 10.0.4 allows a malicious user to inject arbitrary HTML into the ENS HX Malware Scan Name field, resulting in the exposure of sensitive…

  • CVE-2025-3771highCVSS 7.1Jun 26, 2025

    A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, which can…

  • CVE-2025-3773Jun 26, 2025

    A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in…

  • CVE-2025-3722Jun 26, 2025

    A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System…

  • WID-SEC-2025-0872mediumCVSS 6.5Apr 23, 2025

    Affected products: Trellix Endpoint Security

  • CVE-2025-0618mediumCVSS 6.5Apr 23, 2025

    A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a specially-crafted tamper protection event to the HX service to trigger an…

  • CVE-2025-0617mediumCVSS 5.9Jan 29, 2025

    An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console.

  • WID-SEC-2024-3738mediumCVSS 5.4Dec 20, 2024

    Affected products: Trellix ePolicy Orchestrator

  • WID-SEC-2024-3673mediumCVSS 7.3Dec 11, 2024

    Affected products: Trellix Data Loss Prevention

  • CVE-2024-11482criticalCVSS 9.8Nov 29, 2024

    A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.

  • WID-SEC-2024-3538highCVSS 9.8Nov 25, 2024

    Affected products: Trellix Enterprise Security Manager

  • WID-SEC-2024-1771mediumCVSS 7.3Aug 07, 2024

    Affected products: Trellix ePolicy Orchestrator

  • WID-SEC-2024-1164highCVSS 8.0May 17, 2024

    Affected products: Trellix ePolicy Orchestrator

  • WID-SEC-2024-1085mediumCVSS 7.3May 10, 2024

    Affected products: Trellix Data Loss Prevention

  • CVE-2023-6072mediumCVSS 4.6Feb 13, 2024

    A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary…

  • WID-SEC-2024-0061mediumCVSS 6.1Jan 11, 2024

    Affected products: Trellix Endpoint Security

  • WID-SEC-2024-0033highCVSS 8.2Jan 10, 2024

    Affected products: Trellix Agent

  • CVE-2024-0213highCVSS 8.2Jan 09, 2024

    A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated permissions, or cause a Denial of Service (DoS), through exploiting a…

  • CVE-2024-0206highCVSS 7.1Jan 09, 2024

    A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of…

  • WID-SEC-2023-3026highCVSS 8.1Nov 29, 2023

    Affected products: Trellix Enterprise Security Manager

  • WID-SEC-2023-2963highCVSS 8.0Nov 17, 2023

    Affected products: Trellix ePolicy Orchestrator

  • WID-SEC-2023-2732mediumCVSS 7.3Oct 24, 2023

    Affected products: Trellix Data Loss Prevention

  • WID-SEC-2023-2435mediumCVSS 5.5Sep 25, 2023

    Affected products: Trellix Endpoint Security

  • WID-SEC-2023-2360mediumCVSS 6.2Sep 15, 2023

    Affected products: Trellix Secure Web Gateway

  • WID-SEC-2023-2349mediumCVSS 7.1Sep 14, 2023

    Affected products: Trellix Data Loss Prevention

  • WID-SEC-2023-1888mediumCVSS 5.4Jul 26, 2023

    Affected products: Trellix ePolicy Orchestrator

  • WID-SEC-2023-1598highCVSS 8.1Jun 29, 2023

    Affected products: Trellix Enterprise Security Manager

  • WID-SEC-2023-1387mediumCVSS 6.5Jun 07, 2023

    Affected products: Trellix Agent

  • CVE-2023-0976mediumCVSS 6.3Jun 07, 2023

    A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Agent/bin/ folder.

  • CVE-2023-1388mediumCVSS 6.3Jun 07, 2023

    A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory block, resulting in the service becoming…

  • CVE-2023-0977mediumCVSS 6.7Apr 03, 2023

    A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page heap in the macmnsvc process memory block…

  • CVE-2023-0975highCVSS 8.2Apr 03, 2023

    A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it…

  • WID-SEC-2023-0817highCVSS 8.2Mar 31, 2023

    Affected products: Trellix Agent

  • CVE-2023-0978mediumCVSS 6.4Mar 13, 2023

    A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using…

  • WID-SEC-2023-0247mediumCVSS 6.7Feb 06, 2023

    Affected products: Trellix Data Loss Prevention

  • CVE-2023-0400mediumCVSS 5.9Feb 01, 2023

    The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0.

  • WID-SEC-2023-0106mediumCVSS 6.1Jan 18, 2023

    Affected products: Trellix Secure Web Gateway

  • CVE-2023-0221mediumCVSS 4.4Jan 13, 2023

    Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by ACC using…

  • CVE-2022-4326mediumCVSS 5.5Dec 16, 2022

    Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administrator privileges to bypass the product…

  • CVE-2022-3859mediumCVSS 6.7Nov 30, 2022

    An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8.

  • CVE-2022-2188mediumCVSS 6.5Nov 07, 2022

    Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory.

  • CVE-2022-3340mediumCVSS 5.9Nov 04, 2022

    XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface part of the…

  • CVE-2022-3338mediumCVSS 5.4Oct 18, 2022

    An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack.

  • CVE-2022-3339mediumCVSS 5.4Oct 18, 2022

    A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 Update 14 allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session…

Which registers contributed

RegisterOperated byEntriesLatest
European Vulnerability DatabaseENISA, European Union27Jul 14, 2026
CERT-Bund security advisoriesBSI, Federal Republic of Germany25Feb 26, 2026
National Vulnerability DatabaseNIST, United States Department of Commerce2Jun 26, 2026

The entry counts here are the raw register totals for Trellix, before attribution. They are larger than the list above for exactly that reason.

Questions this page answers

How many vulnerabilities does Trellix have?

52 advisories in this record are tied by a register to a product of Trellix. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.

Are any Trellix vulnerabilities being actively exploited?

None of the 52 records here appears in the CISA catalogue of known exploited vulnerabilities. That catalogue is not exhaustive: it lists what CISA has confirmed as exploited, so absence from it is not proof that nothing has been exploited.

Why does this page show fewer CVEs for Trellix than other sites?

Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 0 register entries name Trellix without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.

Where do the Trellix advisories on this page come from?

From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany); National Vulnerability Database (NIST, United States Department of Commerce). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.

Does a long advisory list mean Trellix is insecure?

No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.

A list of advisories is not a risk assessment

What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.

The full Trellix record, including sources and open questions

Trellix vulnerabilities: all 52 advisories on record, with sources | DecisionOS by nexalign