ePO - On-prem 5.10.0 Service pack 1 Update 6 supports new features and addresses the known issues, including security fixes and performance.
We recommend that you always upgrade ePO 5.10.0 with the latest release as soon as possible.
Release details
Trellix ePolicy Orchestrator - On-premises Cumulative Updater Tool ePO_5.10.0_SP1_UP6_1895.
Release Date: December 9, 2025
For the complete list of release dates and build numbers, see Product release information in KB51569.
Rating
The rating defines the urgency for installing this update.
This release is mandatory for all environments. You must apply these updates to maintain a viable and supported product. For more information, see KB51560.
New features
OAuth 2 for Email Server: Added support for OAuth 2 authentication for email server settings, supporting Google and Microsoft providers to replace Basic Authentication. For details, see KB14952.
Default Trellix source site now supports HTTPS communication via Port 443 for enhanced security. Port 80 remains available for legacy agent support. For details, see Create source sites.
Note
Automatic fallback to Port 80 (HTTP) is not supported if secure communication fails. To use the non-secure port, secure communication must be manually disabled.
Enhancements
Enhanced API capabilities: The system.find remote command now returns additional system context, including OS Platform (Server/Workstation), Installed Products list, and Domain Controller status (Requires Trellix Agent 5.8.3 or later). For more information, see View system information details.
TLS 1.3 Browser Support: The ePO - On-prem console now supports TLS 1.3 for browser-based access. Agent-handler communication continues to use existing TLS protocols.
ePO supports the following versions of core third-party components:
Tomcat version 9.0.112
Java version 1.8.0_471
MSOLEDB version 18.7.4
BC-FIPS version 2.0.0
BCTLS-FIPS version 2.0.19
Spring Framework version 5.3.45
For more information, see KB61057.
Resolved issues
This update contains these resolved issues.
Product manageability
Reference | Resolution |
|---|---|
EPO-12192 | Fixes the issue that caused the server task "Update Master Repository" to fail after updating ePO to SP1 Update 2. The Master Repository update task now completes successfully. |
EPO-12241 | Fixes the issue where, after a successful data query, not all graphics were displayed on the dashboard in ePO 5.10 SP1 Update 2. |
EPO-12808 | Fixes the issue where the ePO tag was not displayed correctly under the Server Task configuration, preventing users from properly assigning tags through server tasks. |
EPO-12984 | Fixes an issue where Server Tasks failed to save or display the text entered in the Report runtime parameters column when configuring a "Run Report" action. |
EPO-13006 | Fixes the issue in On-Prem ePO 5.10 SP1 CU5's Firewall Rules / TACC Policies where partial JavaScript code was displayed and the edit policy page appeared blank. |
EPO-13019 | Fixes the issue that caused an error during data conversion from a varchar to a datetime type. |
EPO-13029 | Fixes the issue during Active Directory (AD) synchronization that led to the creation of duplicate systems in the ePO console. The synchronization process now correctly identifies existing systems, preventing duplication. |
EPO-13041 | Fixes the issue where the configured HTTPS Port would revert to its default value when an administrator edited an HTTP distributed repository. |
EPO-13043 | Fixes the issue where a blank page was displayed when attempting to access the View Effective Policy for either Exploit Prevention or Web Control. Users can now successfully view the effective policy pages. |
EPO-13045 | Fixes the issue within the Active Directory/NT Domain synchronization server task where the "Select synchronized groups" button failed to load the necessary resource. |
EPO-13070 | Fixes an issue where the Edit Assignment page failed to load when attempting to configure a multi-slot policy for ENS Exploit Prevention on a single system. |
EPO-13137 | Fixes the issue causing Microsoft Entra integration (formerly Azure AD) to fail in ePO 5.10 SP1 U5 with the error "Unknown error occurred during test connection". |
EPO-16474 | Fixed an issue where the System.Find command failed with an authorization error for non-administrator users after the update. To resolve this, ensure that the affected permission sets have Apply, exclude, and clear tags selected in the Systems category. For more details, see KB15218. |
Security
Reference | Resolution |
|---|---|
SAG-172 | Implements enhanced security by adding the missing "SameSite" attribute to cookies, improving protection against cross-site request forgery (CSRF). |
SAG-186 | Resolves critical vulnerabilities by fixing IDOR and Command Injection, preventing unauthorized access and arbitrary command deployment. For details, see the Security Bulletin 15066. |
SAG-213 | Upgrades the Apache httpd version to 2.4.63 to resolve known vulnerabilities and enhance server security. |
SAG-233 | Resolves critical vulnerabilities by upgrading the Jackson Databind and PostgreSQL JAR components. |
SAG-254 | Resolves a security vulnerability (CVE-2025-59250) by upgrading the internal Microsoft SQL JDBC driver from version 12.2.0.jre8 to 12.2.1.jre8, enhancing the security and integrity of database communication. |
Known issues
For a list of known issues in this product release, see ePO - On-prem 5.10.0 Known Issues (KB90382).
Additional information
Installation instruction: To install, repair, and verify the cumulative update and Agent Handler updates, refer Cumulative update installation procedures.
Important details about Service pack 1 Update 4: Before you upgrade refer the Mandatory Prerequisites and Upgrade Requirements for SHA-2 migration, and minimum OS/SQL requirements.
Disaster recovery: For information about disaster recovery, restoration, and required repair package versions, see Disaster recovery and restoration scenarios.