Junglewise Threat Intelligence

CVE-2025-7958: Trellix Network Security CM and NX code injection in Alert artifact details

CVE-2025-7958 · Severity: info · CVSS 6.7 · Published 2026-06-26

Executive brief

A security flaw in Trellix Network Security management and sensor appliances could allow an authorized administrator to execute unauthorized commands on the system. By manipulating specific alert details within the web management interface, a user with high-level access can bypass security controls to run arbitrary code. This could lead to a complete compromise of the security appliance, potentially allowing an attacker to hide their activities or disrupt network monitoring operations.

Technical details

A code injection vulnerability exists in the web management interface of Trellix Network Security CM and NX appliances. The flaw is located within the handling of Alert artifact details, where insufficient input validation allows a locally authenticated user with administrative privileges to inject and execute arbitrary code. While the attack requires existing administrative credentials, successful exploitation results in full system compromise at the level of the web service or underlying operating system. Users should refer to Trellix security bulletin SB10433 for specific version fixes and patching instructions.

Affected products

  • Trellix Network Security CM
  • Trellix Network Security NX

Timeline

  • 2026-06-26: disclosed

References