CVE-2026-12588: Trellix HX Console

Medium severity, CVSS 6.0. EPSS: 0.3% chance of exploitation in the next 30 days.

An attacker with access to an HX 10.0.0  and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service.

Affected products

  • Trellix Trellix HX Console: version 5.1.1 only

Published 2026-07-14. Last modified 2026-07-15.