Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Trellix

First CVE: Nov 4, 2022Active for: 4 yearsTotal CVEs: 32
37.5
VTI Score
Medium

Trellix develops security infrastructure products spanning endpoint agents, enterprise management platforms, and intrusion-prevention systems that defend large-scale network environments. The vendor's vulnerability footprint remains relatively concentrated across a modest product portfolio but carries outsized significance given the management and detection capabilities these systems hold over downstream systems. The recurring weakness classes—input validation and neutralization flaws leading to cross-site scripting and OS command injection, path traversal conditions, and authentication-bypass patterns—reflect the complexity of parsing untrusted input and managing privilege boundaries in management interfaces and network monitoring appliances. Defenders should treat Trellix platform disclosures as broadly relevant to their detection and response posture, particularly for management-tier access controls and agent communication channels. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
32
Total CVEs
More Total CVEs than 97% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Trellix over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2022
3 years ago
Most Recent CVE
Feb 24, 2026
150 days ago

Self-Reporting Analysis

Of all the CVEs published by Trellix as a CNA, 9.5% affect products that Trellix develops as a vendor.

90.5%
Self-reported: 32 (9.5%)
Third-party: 304 (90.5%)

Of all the CVEs published that affect products developed by Trellix, 100.0% are self-published by Trellix as a CNA.

100.0%
Self-published: 32 (100.0%)
Other CNAs: 0 (0.0%)

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-0214MEDIUM
A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to 12.0.1 allows a remote attack
Jan 18, 20236.131NOYES
CVE-2023-0400HIGH
The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from
Feb 2, 20238.226NONO
CVE-2025-14963HIGH
A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bri
Feb 24, 20267.825NONO
CVE-2024-11482CRITICAL
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.
Nov 29, 20249.825NONO
CVE-2023-0978MEDIUM
A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands usi
Mar 13, 20236.725NONO
CVE-2023-3314HIGH
A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process exe
Jul 3, 20238.824NONO
CVE-2023-0976HIGH
A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Agent/bin/ folder. The malicious
Jun 7, 20237.824NONO
CVE-2023-0975HIGH
A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables
Apr 3, 20237.824NONO
CVE-2022-3340HIGH
XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface par
Nov 4, 20227.224NONO
CVE-2024-5957HIGH
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
Sep 5, 20247.523NONO
View all 32 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products32 CVEs
38%
59%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local17 (53.1%)
Network15 (46.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (78.1%)
Unknown0 (0.0%)
Required7 (21.9%)
Privileges Required
Low17 (53.1%)
High7 (21.9%)
None8 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Trellix.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Trellix — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Trellix's Products

View all 1 CNAs →

Top CWEs