Back to Database
Status published
High
CVE-2025-7958
A Code Injection vulnerability existed in Trellix Network Security CM...
Vulnerability Description
A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artifact details.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-7958
Credits & Attribution
No credits recorded in the NVD database.
More from Trellix
View All →CVE-2025-5967
A stored cross-site scripting vulnerability in ENS HX 10.0.4 allows...
Medium
5.3
CVE-2025-3773
A sensitive information exposure vulnerability in System Information Reporter...
Unknown
0
CVE-2025-3771
A path or symbolic link manipulation vulnerability in SIR 1.0.3...
High
7.2
CVE-2025-3722
A path traversal vulnerability in System Information Reporter (SIR) 1.0.3...
Unknown
0
CVE-2025-14963
A vulnerability identified in the HX Agent driver file fekern.sys allowed...
Medium
6.2
Affected Vendor
Trellix
View all reports →Affected Software
Trellix Network Security NX, EX, FX, AX, and CMS
Vulnerable Versions:
10.0.4
Timeline
Official Publish:
June 26th, 2026
Last Modified:
June 26th, 2026
Added to House:
July 22nd, 2026