CVE-2025-3928High· 8.8▾ Abyssal⚠ Exploited in the wildPoC availableCommvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fi…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 48.4 · likelihood 0.5 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due May 19, 2025
Last analysed / modified upstream
2.3%
Added to the CISA catalog on Apr 28, 2025. Federal remediation due May 19, 2025. View catalog ↗
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.
commvault >= 11.20.0, < 11.20.217commvault >= 11.28.0, < 11.28.141commvault >= 11.32.0, < 11.32.89commvault >= 11.36.0, < 11.36.46Upgrade past the affected range:
commvault 11.36.46Connected by shared product, vendor, weakness, or advisory.
CVE-2023-3519Critical· 9.8Unauthenticated remote code execution
CVE-2021-44529Critical· 9.8A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
CVE-2021-22205Critical· 10.0An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9
CVE-2026-77089Critical· 9.8Command Center API contained an authentication bypass issue affecting privilege management
CVE-2026-77091High· 7.8DataCube contained a path traversal issue affecting security feature enforcement
CVE-2026-77092Critical· 9.8Content Extractor contained a deserialization of untrusted data issue affecting privilege management