The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Endpoint Security (ENS) Release Notes 26.11.x - Windows

Prev Next

Release summary

The Trellix Endpoint Security (ENS) 26.11.x is a recommended update that enhances ransomware defense and improves system stability.

Important

Highlight critical information that customers must review before upgrading or deploying the release.

  • Breaking changes (or) Blockers

  • Critical vulnerability fixes

  • Upgrade blockers or restrictions

  • Requires customer actions

  • Compatibility issues

Release rating: This release is recommended for all environments. Apply this update at the earliest convenience.

What's new

This section provides a unified overview of all customer-facing updates introduced in the current release, including new features, feature enhancements, workflow or UI improvements, platform updates, and other significant changes.

  • FIPS 140-3 compliance: This release supports FIPS 140-3 compliance.

  • Expert Rules as Sticky Rules: Trellix Endpoint Security (ENS) now initializes and enforces Exploit Prevention rules during the system boot process to ensure continuous protection immediately after a reboot.

  • Bindlink Support from Expert Rules: Trellix Endpoint Security (ENS) Expert Rules now support intercepting and blocking the creation of Bind Links to prevent unauthorized file link creation.

  • AMSI supportability: Trellix ePolicy Orchestrator (ePO) threat event log event details now include a Detection Message field to provide Antimalware Scan Interface (AMSI) detection context for threat events.

  • Single System Troubleshooting: Trellix Endpoint Security (ENS) provides enhanced single-system troubleshooting features that enable administrative users to retrieve logs and endpoint artifacts remotely from Trellix ePolicy Orchestrator (ePO) without accessing the client machine.

  • Antimalware Scan Interface Protection Enhancement: Trellix Endpoint Security (ENS) now detects and reports threat samples during PowerShell script execution, even when scripts attempt to bypass Antimalware Scan Interface (AMSI) detection by tampering with APIs. When Adaptive Threat Protection (ATP) AMSI is set to observe mode, Trellix ENS logs and reports the tampered script execution without blocking it.

  • FQDN Wildcard Support in Firewall Rules and Groups: Trellix Endpoint Security (ENS) Firewall now supports wildcards in Fully Qualified Domain Names (FQDNs) when configuring firewall rules and rule groups. Administrators can enter wildcard characters in FQDN fields to define firewall rules across multiple subdomains without creating individual entries.

Resolved issues

The following table lists the resolved issues in this release.

Tracking number

Summary

ENSW-132888

During an upgrade of Trellix Endpoint Security (ENS) Standalone to version 20, Access Protection configurations and exclusions reset to default settings. An internal buffer handling issue caused the system to regenerate and reapply the ap.xml file.

ENSW-133077

In standalone managed deployments of Trellix Endpoint Security (ENS) Threat Prevention, the Access Protection setting reverted to enabled after a system restart. This behavior occurred even when Access Protection was explicitly set to Disabled and applied.

ENSW-132480

Executing amcfg.exe during a Secure Shell (SSH) connection failed to check service status or start an on-demand scan (ODS). The command outputted an error stating that the Threat Prevention service was not running. This issue occurred because checking the service status required elevated administrator permissions that SSH user sessions lacked.

ENSW-131708

In the Threat Event log within Trellix ePolicy Orchestrator (ePO), the Threat Source URL field displayed the string reports.allowedSite for certain allowed sites. This string is an internal default initializer that is now properly overridden by the actual site name when Web Control events are logged.

ENSW-129951

Trellix Endpoint Security (ENS) On-Demand Scan (ODS) summary did not display process scanning information after scan completion.

ENSW-131526

The Trellix Endpoint Security (ENS) extension failed to parse virus event.xml files when file paths contained non-character values. The XML 1.0 parser could not process these non-characters, which caused event parsing to fail. Consequently, Trellix ePolicy Orchestrator (ePO) missed the threat events.

ENSW-130209

Opening McTray.exe failed when Domain Name System (DNS) was disabled while Trellix Endpoint Security (ENS) Firewall remained active. This behavior occurred because machine startup or network adapter state changes triggered the ENS Location Awareness module to reconfigure and enforce firewall rules.

ENSW-131120

When the Block all untrusted executables option was enabled in the Firewall options policy, the Log Matching Traffic option failed to display events in the Trellix Endpoint Security (ENS) console.

ENSW-129669

Adaptive Threat Protection (ATP) flagged and stopped the child process conhost.exe due to low reputation when initiated by an excluded parent binary. Though PingCastle.exe was excluded under On-Access Scanning (OAS) and ATP exclusion rules, the parent process propagated its reputation to the child process and submitted it to Joint Classification Module (JCM) scanning. If a parent process is excluded, its child processes are no longer submitted for JCM scanning.

ENSW-125159

An issue where default queries such as Endpoint Security: Threats Detected in the Last 7 Days and Endpoint Security: Threats Detected in the Last 24 hours returned zero results in ePolicy Orchestrator (ePO) SaaS has been resolved. The query definitions now include the "Trellix Endpoint Security" analyzer name and are updated during upgrades.

ENSW-133052

Configuration information stored in the registry is now securely protected using updated key storage mechanisms to resolve a vulnerability reported by an external security researcher.

ENSW-131769

Systems updated to Windows 11 versions 24H2 or 25H2 experienced standard application launch failures and slow user logon times due to a crash of the svchost.exe process in the AppReadiness service. Trellix Endpoint Security (ENS) updated the Exploit Prevention mitigation policy to run in passthrough mode, preventing the service crash and restoring normal logon performance.

ENSW-131763

When a full scan was paused and then resumed in self-managed Endpoint Security (ENS) 10.7.19 and 10.7.20, the elapsed scan time reset to zero instead of maintaining the previous elapsed duration.

ENSW-132696

Trellix Endpoint Security (ENS) Adaptive Threat Protection (ATP) prevented the setup process from executing properly on the system.

ENSW-131725

Custom On-Demand Scans (ODS) did not auto-pause when the system changed to a non-idle state. This issue occurred because Update 19 stopped saving progress for custom ODS scans after a system restart, which left the uScheduledScan registry value set to 0. The system incorrectly treated the resumed scan as a user-initiated scan and failed to auto-pause it when the system returned to a non-idle state.

ENSW-131151

In Trellix Endpoint Security (ENS), the letter e in ePOEvent was inconsistently capitalized in the syslog XML format. The syslog XML element name is now consistently formatted.

ENSW-130163

When you enforce On-Demand Scan (ODS) policies from Trellix ePolicy Orchestrator (Trellix ePO) to a client endpoint, policy changes cause error 0xfffe in EndpointSecurityPlatform_Error.log. Additionally, modifying ODS policies from the client UI causes error code 0x1 (BL_ERROR_INVALID_PARAM) when string properties such as ODS_USERNAME or ODS_PASSWORD are empty. The client UI now correctly passes empty strings instead of NULL values to SetProperty(), which resolves both errors and ensures successful policy enforcement.

ENSW-133297

Systems experienced an intermittent Bugcheck C2 (BAD_POOL_CALLER) Blue Screen of Death (BSOD). The crash failure pointed to Trellix Endpoint Security (ENS) Firewall (ENSFW) driver files, specifically mfefw.exe and mfewfpk.sys.

The issue occurred unpredictably on endpoints running Trellix Endpoint Security (ENS) version 10.7.18. Trellix Endpoint Deployment and Removal Tool (EDRF) version 50.1 was present on some endpoints, but its involvement was not confirmed.

ENSW-129773

Trellix Endpoint Security (ENS) Adaptive Threat Protection (ATP) displays an error message when you save an exclusion path configured with a System Environment Variable (such as %SystemRoot%).

Dynamic Application Control (DAC) policy rules do not directly parse or resolve standalone System Environment Variables. Unlike On-Access Scan (OAS), Exploit Prevention (ExP), and Access Protection (AP), Dynamic Application Control (DAC) requires wildcard prefix notation (such as **\) to parse environmental path syntax.

ENSW-129774

In Trellix Endpoint Security (ENS) Firewall, the module stopped logging events to FirewallEventMonitor.log after an administrator disabled and re-enabled the module. Traffic block events now log immediately after you re-enable the module.

Known issues

For a complete list of known issues, see Trellix Endpoint Security known issues KB82450.

Upgrade and installation information

Release information

This section details the release date, build numbers, and installation packages included in this release.

Release date: [Date]

Build information: 26.11.x

Component

Build Number

Trellix Endpoint Security (ENS) Windows

26.11.x

Prerequisites

  • [Prerequisite 1]

  • [Prerequisite 2]

Upgrade impact

Use this section to describe any expected operational impact during or after installation of the release.

Component

Impact

[Component Name]

[Description of operational impact]

[Component Name]

[Description of operational impact]

Supported upgrade path

The following table lists the supported upgrade paths to the current release.

Current version

Supported upgrade path

[Previous Version 1]

[Upgrade Path Sequence]

[Previous Version 2]

[Upgrade Path Sequence]

[Previous Version 3]

[Upgrade Path Sequence]

Deprecated items

  • [Item Name]: [Description of deprecated feature, command, or service]

  • [Item Name]: [Description of deprecated feature, command, or service]

Additional information

  • Trellix Thrive: Access the unified portal for technical support, product downloads, support case management, diagnostic tools, knowledge base articles, product training, webinars, and community interaction.

    Note

    Access to the Trellix Thrive Portal requires login using valid Trellix customer support, partner, or employee credentials.

  • Trellix Endpoint Security (ENS) Documentation: For detailed technical information, including product guides, release notes, and configuration instructions of [Product Name], visit our documentation portal.

  • [Link to Supported Platforms/Compatibility KB]