The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Enterprise Security Manager 11.6.5 Release Notes

Prev Next

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Release details of Trellix ESM 11.6.5

For release dates and version number, see KB90422.

Rating

The rating defines the urgency for installing this update.

This update is recommended for all environments. Apply this update at the earliest convenience.

Upgrade Considerations

Trellix ESM 11.6.x and higher does not support environments with Distributed TESM configurations.

When upgrading to 11.6.x for the first time the normal process to upgrade HA receivers through the UI needs to be slightly altered.

  1. Refer to Upgrade HA receivers in Trellix Enterprise Security Manager 11.6.x Installation Guide.

  2. Skip step 6.

  3. On step 7a, select the primary receiver instead of the secondary receiver in Receiver Management.

Note

The above steps are only needed when upgrading to 11.6.x for the first time.

New features and changes

This release includes these changes.

  • Trellix ESM now supports a new generation of hardware appliance - ESM generation 6. You can upgrade to Trellix ESM generation 6 appliance hardware to benefit from the latest software developments.

  • FSO integration with ESM – Enables SOAR capabilities for ESM users with TSO licenses.

  • ELM Query performance improvements.

  • Additional Royale UI fixes.

Resolved issues

This release provides resolution for the following issues.

Category

Reference

Resolution

Clustering, Middleware

SIEM-37183

Resolved an issue where passwords for non-management ESM nodes were stored in plain text format in the database.

Correlation

SIEM-39146

Resolved an issue where the ACE was triggering incorrectly on logical Severity comparisons.

Data Source

SIEM-38629

Resolved an issue that caused the UI to freeze and user logins to fail.

ELM Device

SIEM-28870

Fixed an issue where after performing a format on iSCSI, the UI would indicate that a format was required.

ELM Device

SIEM-38555

Resolved an issue that caused rsync_copy to not complete.

ELM Device

SIEM-33588

Resolved an issue where ELM status was Not OK - elmcompressctl not running.

Installation

SIEM-38804

Resolved an issue where the AWS install script failed to install.

Logs

SIEM-38636

Resolved an issue where compressed messages files from a device data export were corrupted.

Watchlists

SIEM-38988

Resolved an issue where ACE rules triggered incorrectly when it was using a NOT logic operator against a Watchlist.

ACE Device

SIEM-39017

Resolved an issue where a correlation data source stopped working on an ENMELM.

ACE Device

SIEM-39204

Resolved an issue with the ACE state database configuration during the upgrade process.

Known issues

For a list of known issues in this product release, see KB90422.