Release summary
The Trellix Endpoint Security (ENS) 26.11.x is a recommended update that enhances ransomware defense and improves system stability.
Important
Highlight critical information that customers must review before upgrading or deploying the release.
Breaking changes (or) Blockers
Critical vulnerability fixes
Upgrade blockers or restrictions
Requires customer actions
Compatibility issues
Release rating: This release is recommended for all environments. Apply this update at the earliest convenience.
What's new
This section provides a unified overview of all customer-facing updates introduced in the current release, including new features, feature enhancements, workflow or UI improvements, platform updates, and other significant changes.
FIPS 140-3 compliance: This release supports FIPS 140-3 compliance.
Expert Rules as Sticky Rules: Trellix Endpoint Security (ENS) now initializes and enforces Exploit Prevention rules during the system boot process to ensure continuous protection immediately after a reboot.
Bindlink Support from Expert Rules: Trellix Endpoint Security (ENS) Expert Rules now support intercepting and blocking the creation of Bind Links to prevent unauthorized file link creation.
AMSI supportability: Trellix ePolicy Orchestrator (ePO) threat event log event details now include a Detection Message field to provide Antimalware Scan Interface (AMSI) detection context for threat events.
Single System Troubleshooting: Trellix Endpoint Security (ENS) provides enhanced single-system troubleshooting features that enable administrative users to retrieve logs and endpoint artifacts remotely from Trellix ePolicy Orchestrator (ePO) without accessing the client machine.
Antimalware Scan Interface Protection Enhancement: Trellix Endpoint Security (ENS) now detects and reports threat samples during PowerShell script execution, even when scripts attempt to bypass Antimalware Scan Interface (AMSI) detection by tampering with APIs. When Adaptive Threat Protection (ATP) AMSI is set to observe mode, Trellix ENS logs and reports the tampered script execution without blocking it.
FQDN Wildcard Support in Firewall Rules and Groups: Trellix Endpoint Security (ENS) Firewall now supports wildcards in Fully Qualified Domain Names (FQDNs) when configuring firewall rules and rule groups. Administrators can enter wildcard characters in FQDN fields to define firewall rules across multiple subdomains without creating individual entries.
Resolved issues
The following table lists the resolved issues in this release.
Tracking number | Summary |
|---|---|
ENSW-132888 | During an upgrade of Trellix Endpoint Security (ENS) Standalone to version 20, Access Protection configurations and exclusions reset to default settings. An internal buffer handling issue caused the system to regenerate and reapply the |
ENSW-133077 | In standalone managed deployments of Trellix Endpoint Security (ENS) Threat Prevention, the Access Protection setting reverted to enabled after a system restart. This behavior occurred even when Access Protection was explicitly set to Disabled and applied. |
ENSW-132480 | Executing |
ENSW-131708 | In the Threat Event log within Trellix ePolicy Orchestrator (ePO), the Threat Source URL field displayed the string |
ENSW-129951 | Trellix Endpoint Security (ENS) On-Demand Scan (ODS) summary did not display process scanning information after scan completion. |
ENSW-131526 | The Trellix Endpoint Security (ENS) extension failed to parse |
ENSW-130209 | Opening |
ENSW-131120 | When the Block all untrusted executables option was enabled in the Firewall options policy, the Log Matching Traffic option failed to display events in the Trellix Endpoint Security (ENS) console. |
ENSW-129669 | Adaptive Threat Protection (ATP) flagged and stopped the child process conhost.exe due to low reputation when initiated by an excluded parent binary. Though PingCastle.exe was excluded under On-Access Scanning (OAS) and ATP exclusion rules, the parent process propagated its reputation to the child process and submitted it to Joint Classification Module (JCM) scanning. If a parent process is excluded, its child processes are no longer submitted for JCM scanning. |
ENSW-125159 | An issue where default queries such as Endpoint Security: Threats Detected in the Last 7 Days and Endpoint Security: Threats Detected in the Last 24 hours returned zero results in ePolicy Orchestrator (ePO) SaaS has been resolved. The query definitions now include the "Trellix Endpoint Security" analyzer name and are updated during upgrades. |
ENSW-133052 | Configuration information stored in the registry is now securely protected using updated key storage mechanisms to resolve a vulnerability reported by an external security researcher. |
ENSW-131769 | Systems updated to Windows 11 versions 24H2 or 25H2 experienced standard application launch failures and slow user logon times due to a crash of the |
ENSW-131763 | When a full scan was paused and then resumed in self-managed Endpoint Security (ENS) 10.7.19 and 10.7.20, the elapsed scan time reset to zero instead of maintaining the previous elapsed duration. |
ENSW-132696 | Trellix Endpoint Security (ENS) Adaptive Threat Protection (ATP) prevented the setup process from executing properly on the system. |
ENSW-131725 | Custom On-Demand Scans (ODS) did not auto-pause when the system changed to a non-idle state. This issue occurred because Update 19 stopped saving progress for custom ODS scans after a system restart, which left the |
ENSW-131151 | In Trellix Endpoint Security (ENS), the letter e in ePOEvent was inconsistently capitalized in the syslog XML format. The syslog XML element name is now consistently formatted. |
ENSW-130163 | When you enforce On-Demand Scan (ODS) policies from Trellix ePolicy Orchestrator (Trellix ePO) to a client endpoint, policy changes cause error |
ENSW-133297 | Systems experienced an intermittent Bugcheck C2 ( The issue occurred unpredictably on endpoints running Trellix Endpoint Security (ENS) version 10.7.18. Trellix Endpoint Deployment and Removal Tool (EDRF) version 50.1 was present on some endpoints, but its involvement was not confirmed. |
ENSW-129773 | Trellix Endpoint Security (ENS) Adaptive Threat Protection (ATP) displays an error message when you save an exclusion path configured with a System Environment Variable (such as Dynamic Application Control (DAC) policy rules do not directly parse or resolve standalone System Environment Variables. Unlike On-Access Scan (OAS), Exploit Prevention (ExP), and Access Protection (AP), Dynamic Application Control (DAC) requires wildcard prefix notation (such as **\) to parse environmental path syntax. |
ENSW-129774 | In Trellix Endpoint Security (ENS) Firewall, the module stopped logging events to |
Known issues
For a complete list of known issues, see Trellix Endpoint Security known issues KB82450.
Upgrade and installation information
Release information
This section details the release date, build numbers, and installation packages included in this release.
Release date: [Date]
Build information: 26.11.x
Component | Build Number |
|---|---|
Trellix Endpoint Security (ENS) Windows | 26.11.x |
Prerequisites
[Prerequisite 1]
[Prerequisite 2]
Upgrade impact
Use this section to describe any expected operational impact during or after installation of the release.
Component | Impact |
|---|---|
[Component Name] | [Description of operational impact] |
[Component Name] | [Description of operational impact] |
Supported upgrade path
The following table lists the supported upgrade paths to the current release.
Current version | Supported upgrade path |
|---|---|
[Previous Version 1] | [Upgrade Path Sequence] |
[Previous Version 2] | [Upgrade Path Sequence] |
[Previous Version 3] | [Upgrade Path Sequence] |
Deprecated items
[Item Name]: [Description of deprecated feature, command, or service]
[Item Name]: [Description of deprecated feature, command, or service]
Additional information
Trellix Thrive: Access the unified portal for technical support, product downloads, support case management, diagnostic tools, knowledge base articles, product training, webinars, and community interaction.
Note
Access to the Trellix Thrive Portal requires login using valid Trellix customer support, partner, or employee credentials.
Trellix Endpoint Security (ENS) Documentation: For detailed technical information, including product guides, release notes, and configuration instructions of [Product Name], visit our documentation portal.