Junglewise Threat Intelligence

CVE-2026-12588: Trellix HX Console denial of service via resource exhaustion

CVE-2026-12588 · Severity: info · CVSS 6 · Published 2026-07-14

Executive brief

Trellix HX Console, a management platform for endpoint security, is vulnerable to a denial-of-service attack. An attacker can send specially crafted data that forces the system to decompress a massive file, exhausting its memory and processing power. This can cause the management console to become unresponsive, preventing security teams from monitoring or responding to threats across the network.

Technical details

A vulnerability classified as CWE-409 (Improper Handling of Highly Compressed Data) exists in Trellix HX Console version 10.0.0 and earlier. An authenticated attacker with network access can submit specially crafted data to the HX console that triggers the decompression of a large file (a 'zip bomb' style attack). This process consumes excessive system resources, leading to a Denial of Service (DoS) condition. The attack requires low privileges but is mitigated by a high attack complexity, likely due to specific data formatting requirements or environmental preconditions.

Affected products

  • Trellix HX Console 10.0.0 and previous versions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References