The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Enterprise Security Manager 11.6.9 Release Notes

Prev Next

Trellix Enterprise Security Manager 11.6.9 addresses known issues.

This release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Release details of Trellix ESM 11.6.9

For release dates and version number, see KB90422.

Rating

The rating defines the urgency for installing this update.

This update is recommended for all environments. Apply this update at the earliest convenience.

Upgrade Considerations

Trellix ESM 11.6.x and higher does not support environments with Distributed TESM configurations.

When upgrading to 11.6.x for the first time the normal process to upgrade HA receivers through the UI needs to be slightly altered.

  1. Refer to Upgrade HA receivers in Trellix Enterprise Security Manager 11.6.x Installation Guide.

  2. Skip step 6.

  3. On step 7a, select the primary receiver instead of the secondary receiver in Receiver Management.

Note

The above steps are only needed when upgrading to 11.6.x for the first time.

Resolved issues

This release provides resolution for the following issues.

Category

Reference

Resolution

Software Upgrade

SIEM-33682

Updated Wireshark package to resolve vulnerabilities.

Software Upgrade

SIEM-33683

Upgraded Samba libs to resolve vulnerabilities.

Software Upgrade

SIEM-33723

Updated rpcbind to version 1.2.6 for CVE-2017-8779.

Software Upgrade

SIEM-39767

Updated Python 3.x package to resolve CVE-2023-24329 and CVE-2019-20907.

Software Upgrade

SIEM-33722

Updated Python 2.x package to resolve CVE-2019-20907.

Software Upgrade

SIEM-33685

Updated Perl libraries to resolve vulnerabilities.

Software Upgrade

SIEM-39434

Updated log4j library version to resolve vulnerabilities.

Alarms, Correlation, ERC Device

SIEM-39555

Resolved an issue with the receiver showing a red flag when the event file dump limit is reached.

Data Source

SIEM-28192

Resolved an issue with Checkpoint opsec connect script when taking empty parameters.

User Interface

SIEM-37425

Resolved an issue that prevented time delta from loading on refresh.

Correlation

SIEM-39748

Fixed an issue that broke Time-based Correlation rules from working as expected.

User Interface

SIEM-37142

Fixed an issue that prevented the drag-and-drop feature from working on the Field Assignment of Advanced Syslog Parser UI.

Device Flags

SIEM-39645

Fixed an issue that caused a red flag in the receiver.

User Interface

SIEM-39642

Fixed an issue that prevented the properties UI for any data source from being opened.

ACE Device, Correlation

SIEM-39749

Fixed an issue with ACE that caused filter settings to be ignored.

ACE Device

SIEM-39760

Fixed an issue where rules failed to load when the rule manager name contained a '.'.

ACE Device

SIEM-39732

Fixed an issue that prevented correlation rules from being triggered for all events within a time period.

User Interface

SIEM-39796

Fixed an issue on Datasource configuration UI which could be exploited for remote command execution vulnerability.

User Interface

SIEM-39781

Resolved an issue with the Case Insensitive field being hidden for IN/NOT IN operators of field match alarm UI.

ACE Device

SIEM-39725

Resolved an issue that caused the decay settings to be used to calculate risk scores were being ignored.

This release provides resolution for the following content issues through a rule update since Trellix ESM 11.6.8.

Category

Reference

Resolution

3rd party

SIEM-39794

Added rules to support new MNEMONICS required for the CISCO Wireless LAN.

Known issues

For a list of known issues in this product release, see KB90422.