{"id":"CVE-2025-7958","title":"A Code Injection vulnerability existed in Trellix Network Security CM and NX","summary":"A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artifact details.","severity":"none","cwe":["CWE-94"],"published":"2026-06-26","updated":"2026-09-29","sourceUpdated":"2026-09-29T20:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-7958","references":[{"url":"https://support.trellix.com/s/article/000015433","label":"trellixpsirt@trellix.com"}],"tags":["nvd"],"epss":0.00309,"epssPercentile":0.21335,"ingestedAt":"2026-09-29T20:46:06.409Z","slug":"CVE-2025-7958","body":"## Overview\n\nA Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artifact details.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}