{"record":"Trellix evidence record","url":"https://nexalign.io/vendors/trellix","vendor":{"slug":"trellix","name":"Trellix","domain":"trellix.com","category":"endpoint-security","categoryLabel":"Endpoint security (EDR and XDR)"},"lastChecked":"2026-07-17T10:20:14.461Z","coverage":{"earliest":"2022-10-18T00:00:00.000Z","latest":"2026-07-14T12:45:10.000Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":60,"kindsOfSource":5,"attributedAdvisories":52,"knownExploited":0,"registerEntriesNotAttributable":0,"practitionerThreads":2,"independentItems":3,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":27,"latest":"2026-07-14T12:45:10.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":25,"latest":"2026-02-26T12:12:00.820Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":2,"latest":"2026-06-26T11:16:30.487Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":3,"latest":"2026-07-03T04:18:51.252Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":3,"latest":"2026-05-04T19:44:43.000Z"}],"advisories":{"shown":6,"total":52,"truncated":true,"fullList":"https://nexalign.io/vendors/trellix/advisories","items":[{"id":"CVE-2026-12588","description":"An attacker with access to an HX 10.0.0  and previous versions, may send specially-crafted data to the HX console.","severity":"medium","cvss":6,"knownExploited":false,"date":"2026-07-14T12:45:10.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43670"]},{"id":"CVE-2025-7958","description":"A Code Injection vulnerability existed in Trellix Network Security CM and NX.","severity":"high","cvss":7.1,"knownExploited":false,"date":"2026-06-26T11:16:30.487Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-7958","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210348"]},{"id":"WID-SEC-2026-0538","description":"Affected products: Trellix Endpoint Security","severity":"medium","cvss":6.4,"knownExploited":false,"date":"2026-02-26T12:12:00.820Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0538"]},{"id":"CVE-2025-14963","description":"A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges.","severity":"medium","cvss":6.2,"knownExploited":false,"date":"2026-02-24T17:11:06.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208089"]},{"id":"WID-SEC-2025-2597","description":"Affected products: Trellix Agent","severity":"high","cvss":8.8,"knownExploited":false,"date":"2025-11-14T08:07:16.689Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2597"]},{"id":"WID-SEC-2025-1609","description":"Affected products: Trellix Endpoint Security, Absolute Secure Access","severity":"low","cvss":4.4,"knownExploited":false,"date":"2025-10-01T06:46:39.380Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1609"]}]},"practitionerThreads":{"shown":2,"total":2,"truncated":false,"items":[{"title":"Trellix discloses data breach after source code repository hack","context":"r/cybersecurity","url":"https://www.reddit.com/r/cybersecurity/comments/1t3sfd5/trellix_discloses_data_breach_after_source_code/","date":"2026-05-04T19:44:43.000Z"},{"title":"Security Advisory: Unauthorised Access to Trellix Internal Source Code","context":"r/cybersecurity","url":"https://www.reddit.com/r/cybersecurity/comments/1t13fw3/security_advisory_unauthorised_access_to_trellix/","date":"2026-05-01T19:31:52.000Z"}]},"independentCoverage":{"shown":3,"total":3,"truncated":false,"items":[{"title":"Trellix Security Platform Reviews & Ratings 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/product/trellix-security-platform","date":null},{"title":"Trellix - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Trellix","date":null},{"title":"Trellix Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/endpoint-protection-platforms/vendor/trellix","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}