VulnSea

commvault has 14 CVEs on record. Disclosure cadence is accelerating: 14 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 11. The median CVSS is 8.8 (high), with 6 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.8
Publish → KEV
Last 90 days
14 prev 0

Products

  • commvault 14
14
Total CVEs
6
Critical
0
CISA KEV
0
Exploited

commvault vulnerabilities

CVEs affecting commvault, newest first. Open any entry for full detail, references, and exploit status.

14 CVEsRSS

CVE-2026-77106High· 8.8
2w ago

Cvlaunchd contained a missing authorization issue affecting command execution authorization

Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, …

Twilightcommvault · commvaultEPSS 0.30%via NVD
CVE-2026-77105High· 8.8
2w ago

CommServe contained a cryptographic signature verification issue affecting privilege management

CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.

Twilightcommvault · commvaultEPSS 0.18%via NVD
CVE-2026-77104High· 7.5
2w ago

CommServe contained a path traversal issue affecting information disclosure

CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

Twilightcommvault · commvaultEPSS 0.37%via NVD
CVE-2026-77103High· 7.5
2w ago

CommServe contained an authentication bypass issue affecting access authorization and information disclosure

CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

Twilightcommvault · commvaultEPSS 0.29%via NVD
CVE-2026-77102High· 7.5
2w ago

CommServe contained a heap-based buffer overflow issue affecting service availability

CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.

Twilightcommvault · commvaultEPSS 0.27%via NVD
CVE-2026-77101High· 7.5
2w ago

CommServe contained a stack-based buffer overflow issue affecting service availability

CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.

Twilightcommvault · commvaultEPSS 0.27%via NVD
CVE-2026-77098Critical· 9.8
2w ago

Private Metrics Server contained an SQL injection condition affecting database operations

Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.

Midnightcommvault · commvaultEPSS 0.26%via NVD
CVE-2026-77097High· 8.2
2w ago

Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability

Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.

Twilightcommvault · commvaultEPSS 0.26%via NVD
CVE-2026-77092Critical· 9.8⚖ disputed
2w ago

Content Extractor contained a deserialization of untrusted data issue affecting privilege management

Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.

Midnightcommvault · commvaultEPSS 0.18%via NVD
CVE-2026-77091High· 7.8
2w ago

DataCube contained a path traversal issue affecting security feature enforcement

DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.

Twilightcommvault · commvaultEPSS 0.13%via NVD
CVE-2026-77089Critical· 9.8
2w ago

Command Center API contained an authentication bypass issue affecting privilege management

Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.

Midnightcommvault · commvaultEPSS 0.33%via NVD
CVE-2026-13738Critical· 9.8
1mo ago

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Web…

Midnightcommvault · commvaultEPSS 0.63%via NVD
CVE-2026-13739Critical· 9.8
1mo ago

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Comm…

Midnightcommvault · commvaultEPSS 0.39%via NVD
CVE-2026-13737Critical· 9.8
1mo ago

CommServe contained an allowlist bypass vulnerability affecting command execution authorization

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Cen…

Midnightcommvault · commvaultEPSS 0.52%via NVD
commvault vulnerabilities (CVEs) · VulnSea