Trellix Intelligent Virtual Execution (IVX) Cloud Security - Commercial US, EU, CAN, APJ, and Gov instances will be upgraded to Release 26R2 beginning on July 27, 2026 at 07:00 UTC and completing on August 3, 2026 at 10:00 UTC.
Note: This upgrade does not require any service or portal downtime.
The IVX Cloud 26R2 release enhances integration visibility, data loss prevention capabilities, and threat analysis efficiency. By optimizing threat analysis efficiency and centralizing security data monitoring, this update allows administrators to better protect and audit their environments.
Details of the features included are as follows:
- View Connector Action Status in Submissions and Alerts — Admins can now view connector action status, the status of automated actions performed by integrations directly from the Submissions and Alerts pages. The new Connector Action Status column provides real-time visibility into whether actions initiated by connected integrations completed successfully or failed, helping administrators monitor and troubleshoot integration activity more effectively.
- Enhanced Connector health and activity statistics — This feature enhances integration troubleshooting by tracking detailed health and activity metrics across third-party connectors. Administrators can review operational metrics, failure details, active user counts, and connector-specific configuration information for supported integrations, including Dropbox, Google Cloud Storage, OneDrive, SharePoint, Microsoft Teams, Salesforce, ServiceNow, Webex, Workday, Zendesk, and Zoom.
- Optimized submission quota — IVX Cloud no longer consumes your operational submission quota for files already pre-marked as malicious by external service providers. This change optimizes resource allocation while maintaining comprehensive reporting within IVX Cloud across integrations including Google Drive, ServiceNow, OneDrive, SharePoint, and Zendesk preserving capacity for unverified files.
- Updated AI models for Trellix Wise — Trellix Wise now uses the latest supported AI models, replacing legacy models that have reached end-of-life (EOL). This update improves platform usability, reporting quality, and overall user experience while ensuring continued access to supported AI capabilities.
Note: This feature is not available for Gov instances.
- Data Security engine support for Google chat —. IVX Cloud can now automatically analyze Google Chat content to help identify sensitive information and enforce Data Loss Prevention (DLP) policies, reducing the risk of data exposure across non-privileged communication channels.
- Updated Sandbox guest images — Upgrades sandbox guest images to version 25R1.1 to optimize detection coverage.
- Extended OS profile support — Added support for additional operating system profiles during API and UI submissions, including Windows 11 (win11x64m) and macOS 10.11.3 (osx-10.11.3). These new profiles provide broader analysis coverage and improved detection accuracy across modern endpoint environments.
Note: Legacy macOS 10.8.2 (osx-10.8.2) is not supported.
- Track submission sources in API workflows — Adds tracking capability for IVX Cloud submissions across internal and external accounts using context variables. This feature provides administrators with deep visibility into submission origins to streamline tracking and monitoring workflows.
- API key expiry notifications — Administrators can now configure email and in-application notifications for upcoming API key expirations. These alerts help teams proactively renew API keys, maintain uninterrupted access to integrations and automated workflows, and reduce the risk of service disruptions caused by expired credentials.
Note: This feature is not available for trial accounts.
- Chrome extension for new accounts — The Chrome extension is now available for newly provisioned customer accounts. The existing extension has been republished under a new hosting account, restoring customer access and enabling deployment for new tenants.
- Customizable dashboards — This release introduces a customizable dashboard experience that replaces the fixed system view. The modular layout provides enhanced visibility into integration submissions, data security posture, DLP activity, quota utilization, and platform health metrics enabling users to customize the view to their operational and security needs. Use the dashboard toggle to switch between the new and legacy dashboard views.
Note: This feature is currently in Beta. Use the BETA UI toggle located in the top header of the IVX Cloud portal to switch between the new and legacy dashboard views or access it by selecting New Dashboard (Beta) under the Investigate section in the Trellix IAM mega menu.
- Tracking malicious messages in Google chat — The system now automatically delivers malicious content alerts as direct inline replies to the original message thread in Google chat spaces and direct messages using Google workspace APIs. This capability enables users to immediately identify which specific message triggered the threat verdict.
- Unified notification interface — Introduces a notification bell icon to the console navigation interface. This provides administrators with a single, centralized view of activity alerts and operational updates aggregated across multiple platform components, including API key modifications and integration status changes. This unified view ensures immediate visibility into critical system events and security operations.
- Global geographic tracking for submissions — Integrates Geo IP lookup capability into IVX Cloud to resolve the geographic origins of submitted IP addresses and mapped URL domains. This integration automatically populates an interactive Global Threat Map dashboard widget, enabling administrators to visually track submission sources on a world graph, analyze regional trends, and map attack origins.
- Health integration API enhancements — Added the connector_registration_id key to the response payload of the /health/integration API endpoint. Administrators can now view unique connector IDs directly inside health check data. This simplifies connecting with external monitoring tools such as Splunk to automate incident tracking and identify specific integrations.