Trellix develops security infrastructure products spanning endpoint agents, enterprise management platforms, and intrusion-prevention systems that defend large-scale network environments. The vendor's vulnerability footprint remains relatively concentrated across a modest product portfolio but carries outsized significance given the management and detection capabilities these systems hold over downstream systems. The recurring weakness classes—input validation and neutralization flaws leading to cross-site scripting and OS command injection, path traversal conditions, and authentication-bypass patterns—reflect the complexity of parsing untrusted input and managing privilege boundaries in management interfaces and network monitoring appliances. Defenders should treat Trellix platform disclosures as broadly relevant to their detection and response posture, particularly for management-tier access controls and agent communication channels. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trellix over time
Of all the CVEs published by Trellix as a CNA, 9.5% affect products that Trellix develops as a vendor.
Of all the CVEs published that affect products developed by Trellix, 100.0% are self-published by Trellix as a CNA.
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0214MEDIUM A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to 12.0.1 allows a remote attack | Jan 18, 2023 | 6.1 | 31 | NO | YES |
CVE-2023-0400HIGH
The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from | Feb 2, 2023 | 8.2 | 26 | NO | NO |
CVE-2025-14963HIGH A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bri | Feb 24, 2026 | 7.8 | 25 | NO | NO |
CVE-2024-11482CRITICAL A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user. | Nov 29, 2024 | 9.8 | 25 | NO | NO |
CVE-2023-0978MEDIUM
A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands usi | Mar 13, 2023 | 6.7 | 25 | NO | NO |
CVE-2023-3314HIGH
A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process exe | Jul 3, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-0976HIGH
A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Agent/bin/ folder. The malicious | Jun 7, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-0975HIGH
A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables | Apr 3, 2023 | 7.8 | 24 | NO | NO |
CVE-2022-3340HIGH XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface par | Nov 4, 2022 | 7.2 | 24 | NO | NO |
CVE-2024-5957HIGH This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager. | Sep 5, 2024 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trellix.
Media articles that mention a CVE ID that affects a product developed by Trellix — matched by CVE ID, not by vendor name.