ePO - On-prem 5.10.0 Service pack 1 Update 5 supports new features and addresses the known issues, including security fixes and performance.
We recommend that you always upgrade ePO 5.10.0 with the latest release as soon as possible.
Release Details
Trellix ePolicy Orchestrator - On-premises Cumulative Updater Tool ePO_5.10.0_SP1_UP5_1818.
Release Date: August 11, 2025
For the complete list of release dates and build numbers, see Product release information in KB51569.
Rating
The rating defines the urgency for installing this update.
This release is mandatory for all environments. You must apply these updates to maintain a viable and supported product. For more information, see KB51560.
New features
ePO - On-prem now supports integration with Microsoft Entra ID (formerly Azure AD), which allows for device synchronization and enable user-based policy enforcement.
Introduces the Rolled-Up User Audit feature, which allows administrators to collect and view user login and audit information from multiple ePO servers in a single reporting server. This helps to monitor and report on user accounts and login activity across your environment.
As an Administrator, you can configure an Automatic Response in ePO - On-prem to insert user's email address and send notifications directly to users who request approval for blocked applications.
ePO - On-prem now displays a warning message before deleting a system or group from the System Tree if it has point products installed.
Introduces the Multiple Tabs option to manage how ePO functions when used across multiple browser tabs. To prevent data conflicts, administrators can configure this feature to either warn users editing the same item simultaneously or restrict all multi-tab use for a single session.
Enhancements
Upgraded Tomcat version to 9.0.106
Java version 1.8.0_441
MSOLEDB 18.7.4
BC-FIPS 2.0.0
BCTLS-FIPS 2.0.19
Active Directory User Logon now renamed to Directory Server User Logon to accommodate new options for enabling LDAP and Entra ID users for logon. For more details, see KB15003.
Resolved issues
This update contains these resolved issues.
Functional stability
Reference | Resolution |
|---|---|
EPO-11343 | Fixes the port conflict issue with the Tomcat shutdown port, which resulted in the error "java.net.BindException: Address already in use: JVM_Bind". |
EPO-12380 | Fixes the issue that prevented users from adding a second IP range under the CSR report. |
EPO-12437 | SADR replication failed after updating to SP1 CU3. This issue is now resolved. |
EPO-12471 | Fixes the issue where ePO 5.10 Service Pack 1 Update 3 using IDP (Keycloak using SAML) configuration was unable to login. |
EPO-12523 | With ePO SP1 CU3, the LDAP Location column was blank on the System Tree page. This issue is now resolved. |
EPO-12532 | The filter for the last system boot in the ePO Query builder did not use the datetime format.This issue is now resolved. |
EPO-12615 | Fixes the issue where a scroll bar was missing on the Policy Ownership page. |
EPO-12623 | Fixes the issue where a server task with two actions to run query and delete systems would not be saved. |
EPO-12634 | Fixes the issue where Insights ePO queries were failing with the error "java.sql.SQLException". |
EPO-12641 | Fixes the issue that prevented users from building custom queries with CSP enabled on the ePO server. |
EPO-12650 | Fixes the issue where the Agent entry was missing under the Products tab in System Tree, even though the EPOAGENT3000 entry was visible in the EPOProductProperties for the same system. |
EPO-12660 | New Subgroup window title is incorrect in Japanese. This issue is now resolved. |
EPO-12671 | Fixes the issue by making "Logon Title Prefix" customizable under Server Settings. |
EPO-12672 | Users were unable to edit an Agent Handler Assignment Rule after enabling CSP with CU4. This issue is now resolved. |
EPO-12680 | Fixes the issue that prevented the "Logon Title Prefix" from being set to a blank or NULL value. |
EPO-12706 | The HSTS max-age value is now updated to 63072000 seconds (2 years) as per OWASP recommendations. |
EPO-12718 | Fixes the issue where the Trellix ENS FW policy was corrupted and non-editable. |
EPO-12752 | Fixes the Moment.js vulnerability identified by Qualys by updating the Moment.js version to 2.30.1. |
EPO-12820 | Fixes the issue where a Server Task could not be saved when two query conditions were used. |
EPO-13006 | Fixes the issue where after upgrading to ePO 5.10 SP1 CU5, the UI now correctly shows large, complex policies when you view or edit them. |
EPU-621 | Fixes the issue where updating to SP1 CU2 or SP1 CU3 modified the |
Security Hardening
Reference | Resolution |
|---|---|
SAG-141 | Fixes multiple vulnerabilities identified by the user during a penetration test conducted with the Burp Suite tool. |
SAG-143 | Addresses security vulnerabilities (CVE-2024-38809, CVE-2024-38808) found in the version of the spring-core library used by ePO. |
SAG-170 | Fixes an improper authorization vulnerability where a user could change another user's password without proper rights. |
Known issues
For a list of known issues in this product release, see ePO - On-prem 5.10.0 Known Issues (KB90382).
Additional information
Installation instruction: To install, repair, and verify the cumulative update and Agent Handler updates, refer Cumulative update installation procedures.
Important details about Service pack 1 Update 4: Before you upgrade refer the Mandatory Prerequisites and Upgrade Requirements for SHA-2 migration, and minimum OS/SQL requirements.
Disaster recovery: For information about disaster recovery, restoration, and required repair package versions, see Disaster recovery and restoration scenarios.