ePO - On-prem 5.10.0 Service pack 1 Update 6

Prev Next

ePO - On-prem 5.10.0 Service pack 1 Update 6 supports new features and addresses the known issues, including security fixes and performance.

We recommend that you always upgrade ePO 5.10.0 with the latest release as soon as possible.

Release details

Trellix ePolicy Orchestrator - On-premises Cumulative Updater Tool ePO_5.10.0_SP1_UP6_1895.

Release Date: December 9, 2025

For the complete list of release dates and build numbers, see Product release information in KB51569.

Rating

The rating defines the urgency for installing this update.

This release is mandatory for all environments. You must apply these updates to maintain a viable and supported product. For more information, see KB51560.

New features

  • OAuth 2 for Email Server: Added support for OAuth 2 authentication for email server settings, supporting Google and Microsoft providers to replace Basic Authentication. For details, see KB14952.

  • Default Trellix source site now supports HTTPS communication via Port 443 for enhanced security. Port 80 remains available for legacy agent support. For details, see Create source sites.

    Note

    Automatic fallback to Port 80 (HTTP) is not supported if secure communication fails. To use the non-secure port, secure communication must be manually disabled.

Enhancements

  • Enhanced API capabilities: The system.find remote command now returns additional system context, including OS Platform (Server/Workstation), Installed Products list, and Domain Controller status (Requires Trellix Agent 5.8.3 or later). For more information, see View system information details.

  • TLS 1.3 Browser Support: The ePO - On-prem console now supports TLS 1.3 for browser-based access. Agent-handler communication continues to use existing TLS protocols.

  • ePO supports the following versions of core third-party components:

    • Tomcat version 9.0.112

    • Java version 1.8.0_471

    • MSOLEDB version 18.7.4

    • BC-FIPS version 2.0.0

    • BCTLS-FIPS version 2.0.19

    • Spring Framework version 5.3.45

    For more information, see KB61057.

Resolved issues

This update contains these resolved issues.

Product manageability

Reference

Resolution

EPO-12192

Fixes the issue that caused the server task "Update Master Repository" to fail after updating ePO to SP1 Update 2. The Master Repository update task now completes successfully.

EPO-12241

Fixes the issue where, after a successful data query, not all graphics were displayed on the dashboard in ePO 5.10 SP1 Update 2.

EPO-12808

Fixes the issue where the ePO tag was not displayed correctly under the Server Task configuration, preventing users from properly assigning tags through server tasks.

EPO-12984

Fixes an issue where Server Tasks failed to save or display the text entered in the Report runtime parameters column when configuring a "Run Report" action.

EPO-13006

Fixes the issue in On-Prem ePO 5.10 SP1 CU5's Firewall Rules / TACC Policies where partial JavaScript code was displayed and the edit policy page appeared blank.

EPO-13019

Fixes the issue that caused an error during data conversion from a varchar to a datetime type.

EPO-13029

Fixes the issue during Active Directory (AD) synchronization that led to the creation of duplicate systems in the ePO console. The synchronization process now correctly identifies existing systems, preventing duplication.

EPO-13041

Fixes the issue where the configured HTTPS Port would revert to its default value when an administrator edited an HTTP distributed repository.

EPO-13043

Fixes the issue where a blank page was displayed when attempting to access the View Effective Policy for either Exploit Prevention or Web Control. Users can now successfully view the effective policy pages.

EPO-13045

Fixes the issue within the Active Directory/NT Domain synchronization server task where the "Select synchronized groups" button failed to load the necessary resource.

EPO-13070

Fixes an issue where the Edit Assignment page failed to load when attempting to configure a multi-slot policy for ENS Exploit Prevention on a single system.

EPO-13137

Fixes the issue causing Microsoft Entra integration (formerly Azure AD) to fail in ePO 5.10 SP1 U5 with the error "Unknown error occurred during test connection".

EPO-16474

Fixed an issue where the System.Find command failed with an authorization error for non-administrator users after the update. To resolve this, ensure that the affected permission sets have Apply, exclude, and clear tags selected in the Systems category. For more details, see KB15218.

Security

Reference

Resolution

SAG-172

Implements enhanced security by adding the missing "SameSite" attribute to cookies, improving protection against cross-site request forgery (CSRF).

SAG-186

Resolves critical vulnerabilities by fixing IDOR and Command Injection, preventing unauthorized access and arbitrary command deployment. For details, see the Security Bulletin 15066.

SAG-213

Upgrades the Apache httpd version to 2.4.63 to resolve known vulnerabilities and enhance server security.

SAG-233

Resolves critical vulnerabilities by upgrading the Jackson Databind and PostgreSQL JAR components.

SAG-254

Resolves a security vulnerability (CVE-2025-59250) by upgrading the internal Microsoft SQL JDBC driver from version 12.2.0.jre8 to 12.2.1.jre8, enhancing the security and integrity of database communication.

Known issues

For a list of known issues in this product release, see ePO - On-prem 5.10.0 Known Issues (KB90382).

Additional information