ePO - On-prem 5.10.0 Service pack 1 Update 7 Release Notes

Prev Next

Release summary

This release updates security standards, simplifies certificate setup, and fixes software issues in Trellix ePolicy Orchestrator (ePO) On-prem 5.10.0 Service Pack 1 Update 7.

  • Downloads and links root CA certificates automatically for the main Trellix update site (update.nai.com), keeping HTTPS connections safe without manual steps.

  • Secures communication between the ePO server and Trellix Agent. This capability becomes available once TA adds TLS 1.3 support; until then, communication continues using TLS 1.2.

  • Lets administrators specify custom Subject Alternative Name (SAN) values when creating leaf certificates for Agent Handlers.

  • Upgrades third-party software—including Apache Tomcat, Apache Log4j, and OpenSSL—to patch known security bugs.

  • Resolves SSL and connection errors to keep threat data sending correctly to Syslog servers.

  • Fixes display issues in the System Tree about unexpected duplicate system entries and gives admins an option to turn off duplicate row filtering.

Important

  • Agent 4.x communication loss: Endpoints running Trellix Agent versions older than 5.0.0 will lose connection to the ePO server after this update. Upgrade all Agents to version 5.0.0 or later before installing.

  • Disaster Recovery script: Running DR_Update7.bat followed by a Cumulative Update (CU) repair resolves snapshot Disaster Recovery restore errors on SP1 Update 7 by correcting Apache service configuration and restoring valid Agent-to-Server communication keys.

  • TLS 1.3 requirement: ePO now supports TLS 1.3 for communication with Trellix Agent (TA). This becomes active once TA adds TLS 1.3 support; ePO continues to use TLS 1.2 with existing Agents until then.

Release rating: Recommended

What's new

Automatic certificate management for the Trellix source site: ePO now automatically downloads and links the certificate for the default TrellixHttp source site update.nai.com using the Root Certificate Authority (CA). This eliminates the need for manual certificate management and ensures secure HTTPS communication.

TLS 1.3 support for agent-to-server communication: ePO - On-prem now supports TLS 1.3, providing enhanced security for communication between ePO and Trellix Agent (TA). When Trellix Agent that communicate with ePO add TLS 1.3 support, this capability becomes available for you to use. Until then, the Trellix Agent will continue to communicate with ePO using TLS 1.2. To ensure uninterrupted operations, ePO - On-prem continues to support TLS 1.2 for backward compatibility with existing endpoints.

Custom Subject Alternative Name support for Agent Handler certificates:  ePO On-prem now supports custom Subject Alternative Name (SAN) values when generating leaf certificates for Agent Handlers (AH). This capability allows administrators to specify custom domain names during certificate regeneration by adding the <SAN values> parameter to the remote command execution line. If no custom SAN value is provided, the system defaults to the host Fully Qualified Domain Name (FQDN) while preserving the original Common Name (CN). For more information, see KB90760.

FIPS 140-3 compliance support: ePO On-prem has upgraded its core security libraries and cryptographic modules to comply with the FIPS 140-3. This update applies only to ePO On-prem installations running in FIPS mode. The FIPS standard applicable to your environment depends on your ePO - On-prem version:

  • SP1 version up to Update 6 supports FIPS 140-2

  • SP1 Update 7 supports FIPS 140-3

Third-party component upgrades: This release includes the following third-party component upgrades:

  • Apache Tomcat version 9.0.120

  • Java version 1.8.0_501

  • OpenSSL upgraded from version 1.0.2zj-fips to 3.5.7

  • Apache Log4j upgraded to version 2.25.4

  • Visual Studio for Agent handler upgraded from version 2019 to 2022.

  • MSOLEDB version 18.7.4

  • BC-FIPS version 2.0.0

  • BCTLS-FIPS version 2.0.19

  • Spring Framework version 5.3.49

For more information, see KB61057.

Option to control duplicate row filtering in the System Tree view: ePO now includes a setting that lets administrators enable or disable duplicate row filtering in the System Tree view. Administrators can now enable or disable duplicate row filtering in the System Tree view to customize endpoint display formatting for their workflow.

Resolved issues

General

Issue ID

Description

EPO-13238

Server tasks failed to display accurate datasets when running reports configured with runtime parameters for usernames containing multiple user datasets combined via AND/OR operations.

EPO-12860

A regression of issue EPO-12261 caused a JavaScript execution failure when scrolling through extensive lists within the Tags page or Task Catalog.

EPO-13307

Syslog forwarding errors caused permanent disabling of threat event transmissions to the QRadar Syslog integration due to SSL errors after applying Update 6.

EPO-13280

Executing a wake-up call appended a backslash to the URL, causing the user interface to display a blank screen after four consecutive calls.

EPO-12913

The Last System Boot Time field incorrectly displayed timestamps in Coordinated Universal Time (UTC) format.

EPO-13096

Administrators could not delete more than 1,000 systems simultaneously from the System Tree or via queries after installing CU5.

EPO-13258

The Pending Client Task Approvals review page generated an unexpected system error in Trellix ePO 5.10 SP1 Update 6.

EPO-13240

Chinese language characters displayed incorrectly as question marks (????) in Trellix ePO 5.10 SP1 Update 6.

EPO-13049

The decimal data type size (39) specified for EPOComplianceReporting exceeded the maximum allowed system precision limit of 38.

EPO-13080

The System Tree view generated and displayed duplicate entries.

EPO-13440

An RFC 5424 compliance failure occurred due to missing character escaping within the Syslog STRUCTURED-DATA block.

EPO-13473

Syslog test connections failed over IPv6 architectures following a Trellix ePO upgrade to 5.10.0 SP1 Update 6.

EPO-13447

Non-administrative users could not create or edit tasks from the Edit Tasks menu on a single system in Trellix ePO 5.10.0 SP1 Update 6.

EPO-13551

The New Client Task Assignment button appeared grayed out when editing tasks for a single system from the System Tree.

EPO-13215

Administrators other than the primary administrator could not update or save changes to the Logon Title Prefix setting in Server Settings.

EPO-13080

The System Tree view displayed duplicate rows for endpoints with multiple Security Information and Reporting (SIR) properties, even when only one property was shown as a column.

Installation

Issue ID

Description

EPO-9349

Branch changes failed because packages were randomly selected when the previously selected package version was no longer present in the repository.

EPU-707

The silent Trellix ePO Cumulative Update repair option (resources\app\repair-dr.bat) did not function.

EPO-13228

Upgrading major product versions using the Auto Update feature incorrectly reset the command option variable to "null".

EPO-13488

Administrators could not save configuration changes when updating or setting up a Universal Naming Convention (UNC) source site.

Security fixes

Issue ID

Description

EPO-13285

The Enable HTTPS setting for the default TrellixHttp source site is automatically enabled after an ePO server restart in Trellix ePO 5.10 Service Pack 1 (SP1) Update 6.

SAG-271

The bundled Apache Tomcat library, prior to version 9.0.x, contained a security vulnerability (CVE-2025-66614).

SAG-253

The Software Catalog contained deprecated AngularJS JavaScript libraries with known security vulnerabilities.

SAG-243

A Content Security Policy (CSP) vulnerability existed where a missing base URL compromised the CSP evaluator.

SAG-287

The bundled Apache Log4j library contained known security vulnerabilities (CVE-2026-34477, CVE-2026-34480, and CVE-2026-34478).

SAG-69

The bundled native libcurl package contained a known security vulnerability (PSIR-660 / SIR-660).

SAG-279

The bundled OpenSSL library contained a known security vulnerability (CVE-2026-22796) associated with PKCS#7 handling.

Performance

Issue ID

Description

EPO-11073

Excessive event volumes were directed to the Debug folder after applying Trellix ePO Cumulative Update 15 (CU15), leading to increased disk space consumption.

EPO-13204

An HTTP Error 500 occurred when importing large Endpoint Security (ENS) Firewall policies.

EPO-13524

Configuring a Syslog registered server with an unencrypted port (514) caused the Event Parser to hang during the TLS handshake or stop writing events to the database.

Known issues

For a list of known issues in this product release, see KB90382.

Upgrade and installation information

Release information

This section details the release date, build numbers and installation packages included in this release.

Release date: 11 August, 2026

Build information:

Component

Build Number

ePO - On-prem

ePO_5.10.0_SP1_UP7_2007

Prerequisites

None

Upgrade impact

Use this section to describe any expected operational impact during or after installation of the release.

Component

Impact

ePO Snapshot Disaster Recovery (DR)

A snapshot Disaster Recovery restore on SP1 Update 7 encounters error. Running the DR_Update7.bat file, followed by a Cumulative Update (CU) repair, corrects the Apache service configuration and restores valid Agent-to-Server communication keys. For more information, see KB15675.

Client Task Catalog

Internal background client tasks that incorrectly appeared in the Client Task Catalog are now filtered out. These tasks are no longer visible in the catalog or associated UI workflows. Point product extensions must be updated to supported versions if specific tasks need to be set to visible. For details and extension version requirements, see KB15709.

Supported upgrade path

The following table lists the supported upgrade paths to the current release.

Current version

Supported upgrade path

5.10.0.2428.68

5.10.0.2428.68 → SP1 Update (CU16) → SP1 Update 7

5.10.0.2428.68 + Update 15 or earlier

5.10.0.2428.68 → Update 15 → SP1 Update (CU16) → SP1 Update 7

5.10.0.4098.4 (SP1)

5.10.0.4098.4 (SP1) → SP1 Update 7

SP1 Update 1 to SP1 Update 6

SP1 Update 1 to Update 6 → SP1 Update 7

Deprecated items

ePO On-prem Update 7 removes support for the following components:

  • Trellix Agent versions earlier than 5.0.0: Systems running Agent 4.x will lose communication with the ePO server after this update. Upgrade all managed agents to TA 5.0.0 or later before installing this update.

  • Legacy Mobile Plugin Service and Intel Active Management Technology (AMT) management and support libraries.

See KB15651 for more information.

Additional information