CVE-2025-7958: Code Injection
Published Jun 26, 2026
·Updated
A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artifact details.
Affected Software
2 affected components
Trellix Trellix Network Security CM
Trellix Trellix Network Security NX
Event History
Jun 26, 2026
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
DescriptionWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-7958?
CVE-2025-7958 has a high severity rating of 7.1 on the CVSS scale.
2
What is CVE-2025-7958?
CVE-2025-7958 is a Code Injection vulnerability in Trellix Network Security CM and NX that allows a locally authenticated admin user to execute arbitrary code.
3
How do I remediate CVE-2025-7958?
To address CVE-2025-7958, apply the latest patches or updates provided by Trellix for Network Security CM and NX.
4
Who is affected by CVE-2025-7958?
CVE-2025-7958 affects users of Trellix Network Security CM and NX who have administrative access.
5
Can CVE-2025-7958 be exploited remotely?
CVE-2025-7958 requires local authenticated access, so it cannot be exploited remotely.