The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Upgrading the Trellix software

Prev Next

The HX appliance automatically checks for new system images. Updates are made on an ongoing basis and are easy to download and install.

The HX server also checks for new security content versions, and if configured, automatically downloads and installs them. For more information, see Updating security content and Configuring automatic security updates .

For an appliance that is managed by the Central Management System appliance, software updates should be performed entirely from the Central Management System Web UI. For more information, see the Central Management System Administration Guide.

Important

All Intelligent Virtual Execution - Server appliances in an MVX cluster must run the same system image,  and security content.

On HX servers, do not attempt an upgrade while running an Enterprise Search or data acquisition request.

If you try to start a DMZ server that has not been upgraded to the same version as the HX server, errors will result.

After upgrading your HX software, you should immediately upgrade your associated DMZ server software. When the upgrades are complete, the DMZ server should be booted (restarted) before the server. See Endpoint Security Server boot order .

If your server is in relay mode when it is upgraded, you must re-enable relay mode after the upgrade. See (Optional) reenable Endpoint Security relay mode .

If you need to revert your server to the preceding version of Endpoint Security software after an upgrade, contact Trellix Technical Support for assistance.

Note

Refer to the Trellix DTI Offline Update Portal Guide for upgrade instructions if your server is offline and cannot download updates from the DTI network.

Upgrade times vary, based on the operating environment at your site and the size of the server database.

To reduce upgrade time, you should enable Quiesce mode on your Endpoint Security server before you begin the upgrade process.

Trellix recommends that you use the console (serial) port to upgrade your HX server. If you use the console (serial) port for the upgrade, you can use telnet to communicate with the HX appliance during the upgrade process. For more information about using the console port, see Accessing the physical or serial console.

Do not reboot your server during an upgrade, unless prompted to do so.