The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix EDR Release Notes (Cloud) - August 2026 release

Prev Next

This Trellix Endpoint Detection and Response - Cloud August 2026 release includes new features, enhancements, and resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release.

New or changed

Investigation dashboard retired

The Investigation Dashboard and its corresponding menu entries are retired from the EDR UI.

To continue investigating threats, use the following workflows:

  • Live Threat Analysis using Trellix Wise: Use Ask Wise to trace threat behaviors, summarize incidents, and view attack paths in the Knowledge Graph.

    For more information, see Investigate threats using Generative AI.

  • Investigate historical data using Case Graph Visualizer: Download the investigation historical case data from the EDRF UI and view it offline using the Case Graph Visualizer.

    For more information, see the Trellix Knowledge Base article - How to use Case Graph Visualizer to view Trellix EDR investigation historical data - KB000015761.

View EDR Client version in Device Search and Monitoring dashboards

The EDRF UI now displays the Client version installed on the endpoints. You can view the Client version in the following locations:

  • Device section of the Threat Details pane on the Monitoring dashboard.

  • Device Search details side panel.

Quarantine Linux endpoints in the Monitoring dashboard

The Monitoring dashboard now supports the Quarantine Device and End Quarantine Device actions for Linux endpoints.

For more information, see Quarantine devices using the Monitoring dashboard and End quarantine devices using the Monitoring dashboard.

An information icon appears near the Agent ID field and column headers across the Alerting, Monitoring, Device Search, and Historical Search dashboards. Hover over this icon to display an interactive tooltip. The tooltip explains that an Agent ID displays only for endpoints connected to the Endpoint Security (HX) server.

In EDR UI, the Agent ID field is blank as it is not connected to any Endpoint Security (HX) server .

Context Sensitive Help redirect in EDR UI

In the EDR UI, selecting the Help button now opens the Trellix Documentation Portal home page in a new browser window.

Resolved issues

Reference

Resolution

SEC-213380

Resolves an issue where ePO tags appeared blank for cloud-hosted tenants on the Device Search page. An automated backend service now retrieves and caches ePO - SaaS tags every 24 hours.

SEC-213157

Resolves an issue in ePO - On-prem deployments where the onboarded Trellix EDR tenants ingested data into the US-WEST data center by default because the DXL Cloud Databus URL was set incorrectly. The Correct DXL Cloud Databus URL scheduled server task now automatically updates and maintains the URL to point to the appropriate regional data center.

SEC-216064

Resolves an issue where the Internal error occurred banner continuously displayed on the Trellix EDR Configuration page when tenant registration occurred.

Installation information

The Trellix Endpoint Detection and Response Installation Guide provides information for installing the product and migrating from Trellix® Active Response.

Known issues

For a list of known issues in this product release, see the Trellix Knowledge Base article KB91275.