Release summary
This release updates security standards, simplifies certificate setup, and fixes software issues in Trellix ePolicy Orchestrator (ePO) On-prem 5.10.0 Service Pack 1 Update 7.
Downloads and links root CA certificates automatically for the main Trellix update site (update.nai.com), keeping HTTPS connections safe without manual steps.
Secures communication between the ePO server and Trellix Agent. This capability becomes available once TA adds TLS 1.3 support; until then, communication continues using TLS 1.2.
Lets administrators specify custom Subject Alternative Name (SAN) values when creating leaf certificates for Agent Handlers.
Upgrades third-party software—including Apache Tomcat, Apache Log4j, and OpenSSL—to patch known security bugs.
Resolves SSL and connection errors to keep threat data sending correctly to Syslog servers.
Fixes display issues in the System Tree about unexpected duplicate system entries and gives admins an option to turn off duplicate row filtering.
Important
Agent 4.x communication loss: Endpoints running Trellix Agent versions older than 5.0.0 will lose connection to the ePO server after this update. Upgrade all Agents to version 5.0.0 or later before installing.
Disaster Recovery script: Running
DR_Update7.batfollowed by a Cumulative Update (CU) repair resolves snapshot Disaster Recovery restore errors on SP1 Update 7 by correcting Apache service configuration and restoring valid Agent-to-Server communication keys.TLS 1.3 requirement: ePO now supports TLS 1.3 for communication with Trellix Agent (TA). This becomes active once TA adds TLS 1.3 support; ePO continues to use TLS 1.2 with existing Agents until then.
Release rating: Recommended
What's new
Automatic certificate management for the Trellix source site: ePO now automatically downloads and links the certificate for the default TrellixHttp source site update.nai.com using the Root Certificate Authority (CA). This eliminates the need for manual certificate management and ensures secure HTTPS communication.
TLS 1.3 support for agent-to-server communication: ePO - On-prem now supports TLS 1.3, providing enhanced security for communication between ePO and Trellix Agent (TA). When Trellix Agent that communicate with ePO add TLS 1.3 support, this capability becomes available for you to use. Until then, the Trellix Agent will continue to communicate with ePO using TLS 1.2. To ensure uninterrupted operations, ePO - On-prem continues to support TLS 1.2 for backward compatibility with existing endpoints.
Custom Subject Alternative Name support for Agent Handler certificates: ePO On-prem now supports custom Subject Alternative Name (SAN) values when generating leaf certificates for Agent Handlers (AH). This capability allows administrators to specify custom domain names during certificate regeneration by adding the <SAN values> parameter to the remote command execution line. If no custom SAN value is provided, the system defaults to the host Fully Qualified Domain Name (FQDN) while preserving the original Common Name (CN). For more information, see KB90760.
FIPS 140-3 compliance support: ePO On-prem has upgraded its core security libraries and cryptographic modules to comply with the FIPS 140-3. This update applies only to ePO On-prem installations running in FIPS mode. The FIPS standard applicable to your environment depends on your ePO - On-prem version:
SP1 version up to Update 6 supports FIPS 140-2
SP1 Update 7 supports FIPS 140-3
Third-party component upgrades: This release includes the following third-party component upgrades:
Apache Tomcat version 9.0.120
Java version 1.8.0_501
OpenSSL upgraded from version 1.0.2zj-fips to 3.5.7
Apache Log4j upgraded to version 2.25.4
Visual Studio for Agent handler upgraded from version 2019 to 2022.
MSOLEDB version 18.7.4
BC-FIPS version 2.0.0
BCTLS-FIPS version 2.0.19
Spring Framework version 5.3.49
For more information, see KB61057.
Option to control duplicate row filtering in the System Tree view: ePO now includes a setting that lets administrators enable or disable duplicate row filtering in the System Tree view. Administrators can now enable or disable duplicate row filtering in the System Tree view to customize endpoint display formatting for their workflow.
Resolved issues
General
Issue ID | Description |
|---|---|
EPO-13238 | Server tasks failed to display accurate datasets when running reports configured with runtime parameters for usernames containing multiple user datasets combined via AND/OR operations. |
EPO-12860 | A regression of issue EPO-12261 caused a JavaScript execution failure when scrolling through extensive lists within the Tags page or Task Catalog. |
EPO-13307 | Syslog forwarding errors caused permanent disabling of threat event transmissions to the QRadar Syslog integration due to SSL errors after applying Update 6. |
EPO-13280 | Executing a wake-up call appended a backslash to the URL, causing the user interface to display a blank screen after four consecutive calls. |
EPO-12913 | The Last System Boot Time field incorrectly displayed timestamps in Coordinated Universal Time (UTC) format. |
EPO-13096 | Administrators could not delete more than 1,000 systems simultaneously from the System Tree or via queries after installing CU5. |
EPO-13258 | The Pending Client Task Approvals review page generated an unexpected system error in Trellix ePO 5.10 SP1 Update 6. |
EPO-13240 | Chinese language characters displayed incorrectly as question marks (????) in Trellix ePO 5.10 SP1 Update 6. |
EPO-13049 | The decimal data type size (39) specified for EPOComplianceReporting exceeded the maximum allowed system precision limit of 38. |
EPO-13080 | The System Tree view generated and displayed duplicate entries. |
EPO-13440 | An RFC 5424 compliance failure occurred due to missing character escaping within the Syslog STRUCTURED-DATA block. |
EPO-13473 | Syslog test connections failed over IPv6 architectures following a Trellix ePO upgrade to 5.10.0 SP1 Update 6. |
EPO-13447 | Non-administrative users could not create or edit tasks from the menu on a single system in Trellix ePO 5.10.0 SP1 Update 6. |
EPO-13551 | The New Client Task Assignment button appeared grayed out when editing tasks for a single system from the System Tree. |
EPO-13215 | Administrators other than the primary administrator could not update or save changes to the Logon Title Prefix setting in Server Settings. |
EPO-13080 | The System Tree view displayed duplicate rows for endpoints with multiple Security Information and Reporting (SIR) properties, even when only one property was shown as a column. |
Installation
Issue ID | Description |
|---|---|
EPO-9349 | Branch changes failed because packages were randomly selected when the previously selected package version was no longer present in the repository. |
EPU-707 | The silent Trellix ePO Cumulative Update repair option (resources\app\repair-dr.bat) did not function. |
EPO-13228 | Upgrading major product versions using the Auto Update feature incorrectly reset the command option variable to "null". |
EPO-13488 | Administrators could not save configuration changes when updating or setting up a Universal Naming Convention (UNC) source site. |
Security fixes
Issue ID | Description |
|---|---|
EPO-13285 | The Enable HTTPS setting for the default TrellixHttp source site is automatically enabled after an ePO server restart in Trellix ePO 5.10 Service Pack 1 (SP1) Update 6. |
SAG-271 | The bundled Apache Tomcat library, prior to version 9.0.x, contained a security vulnerability (CVE-2025-66614). |
SAG-253 | The Software Catalog contained deprecated AngularJS JavaScript libraries with known security vulnerabilities. |
SAG-243 | A Content Security Policy (CSP) vulnerability existed where a missing base URL compromised the CSP evaluator. |
SAG-287 | The bundled Apache Log4j library contained known security vulnerabilities (CVE-2026-34477, CVE-2026-34480, and CVE-2026-34478). |
SAG-69 | The bundled native libcurl package contained a known security vulnerability (PSIR-660 / SIR-660). |
SAG-279 | The bundled OpenSSL library contained a known security vulnerability (CVE-2026-22796) associated with PKCS#7 handling. |
Performance
Issue ID | Description |
|---|---|
EPO-11073 | Excessive event volumes were directed to the Debug folder after applying Trellix ePO Cumulative Update 15 (CU15), leading to increased disk space consumption. |
EPO-13204 | An HTTP Error 500 occurred when importing large Endpoint Security (ENS) Firewall policies. |
EPO-13524 | Configuring a Syslog registered server with an unencrypted port (514) caused the Event Parser to hang during the TLS handshake or stop writing events to the database. |
Known issues
For a list of known issues in this product release, see KB90382.
Upgrade and installation information
Release information
This section details the release date, build numbers and installation packages included in this release.
Release date: 11 August, 2026
Build information:
Component | Build Number |
|---|---|
ePO - On-prem | ePO_5.10.0_SP1_UP7_2007 |
Prerequisites
None
Upgrade impact
Use this section to describe any expected operational impact during or after installation of the release.
Component | Impact |
|---|---|
ePO Snapshot Disaster Recovery (DR) | A snapshot Disaster Recovery restore on SP1 Update 7 encounters error. Running the |
Client Task Catalog | Internal background client tasks that incorrectly appeared in the Client Task Catalog are now filtered out. These tasks are no longer visible in the catalog or associated UI workflows. Point product extensions must be updated to supported versions if specific tasks need to be set to visible. For details and extension version requirements, see KB15709. |
Supported upgrade path
The following table lists the supported upgrade paths to the current release.
Current version | Supported upgrade path |
|---|---|
5.10.0.2428.68 | 5.10.0.2428.68 → SP1 Update (CU16) → SP1 Update 7 |
5.10.0.2428.68 + Update 15 or earlier | 5.10.0.2428.68 → Update 15 → SP1 Update (CU16) → SP1 Update 7 |
5.10.0.4098.4 (SP1) | 5.10.0.4098.4 (SP1) → SP1 Update 7 |
SP1 Update 1 to SP1 Update 6 | SP1 Update 1 to Update 6 → SP1 Update 7 |
Deprecated items
ePO On-prem Update 7 removes support for the following components:
Trellix Agent versions earlier than 5.0.0: Systems running Agent 4.x will lose communication with the ePO server after this update. Upgrade all managed agents to TA 5.0.0 or later before installing this update.
Legacy Mobile Plugin Service and Intel Active Management Technology (AMT) management and support libraries.
See KB15651 for more information.
Additional information
Trellix Thrive: Access the unified portal for technical support, product downloads, support case management, diagnostic tools, knowledge base articles, product training, webinars, and community interaction.
Note
Access to the Trellix Thrive Portal requires login using valid Trellix customer support, partner, or employee credentials.
Trellix ePO On-prem Documentation: For detailed technical information, including product guides, release notes, and configuration instructions of ePO On-prem, visit our documentation portal.