CVE-2025-3928

Confirmed PUBLISHED

Commvault Web Server unspecified vulnerability

Commvault · Web Server

398 days faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.7 High EPSS 1.9%

At a Glance

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.

cisa windows linux
CVE Published
Apr 25, 2025
Exploitation Reported
Apr 28, 2025
CVSS
8.7 High
EPSS
1.9%
Remote Low complexity No user interaction

Affected Versions

Vendor Product Version Status
Commvault
Web Server

11.36.0 to < 11.36.46

Affected
Commvault
Web Server

11.36.46

Unaffected
Commvault
Web Server

11.32.0 to < 11.32.89

Affected
Commvault
Web Server

11.32.89

Unaffected
Commvault
Web Server

11.28.0 to < 11.28.141

Affected
Commvault
Web Server

11.28.141

Unaffected
Commvault
Web Server

11.20.0 to < 11.20.217

Affected
Commvault
Web Server

11.20.217

Unaffected

CVE References

  • url documentation.commvault.com · CVE Record https://documentation.commvault.com/securityadvisories/CV_2025_03_1.html
  • url cisa.gov · CVE Record https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_a...
  • url commvault.com · CVE Record https://www.commvault.com/blogs/security-advisory-march-7-2025
  • url commvault.com · CVE Record https://www.commvault.com/blogs/notice-security-advisory-update
  • url cisa.gov · CVE Record https://www.cisa.gov/news-events/alerts/2025/05/22/advisory-update-cy...
Show 1 more reference
  • url commvault.com · CVE Record https://www.commvault.com/blogs/customer-security-update

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.