CVE-2026-12588: Trellix HX Console
Medium severity, CVSS 6.0. EPSS: 0.3% chance of exploitation in the next 30 days.
An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service.
Affected products
- Trellix Trellix HX Console: version 5.1.1 only
Published 2026-07-14. Last modified 2026-07-15.