commvault has 14 CVEs on record. Disclosure cadence is accelerating: 14 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 11. The median CVSS is 8.8 (high), with 6 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.8
- Publish → KEV
- —
- Last 90 days
- 14 prev 0
Worst active — by depth score
CVE-2026-77098Critical· 9.8Private Metrics Server contained an SQL injection condition affecting database operations54CVE-2026-77092Critical· 9.8Content Extractor contained a deserialization of untrusted data issue affecting privilege management54CVE-2026-77089Critical· 9.8Command Center API contained an authentication bypass issue affecting privilege management54CVE-2026-13739Critical· 9.8A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs54CVE-2026-13738Critical· 9.8CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations54
commvault vulnerabilities
CVEs affecting commvault, newest first. Open any entry for full detail, references, and exploit status.
14 CVEsRSS
CVE-2026-77106High· 8.8Cvlaunchd contained a missing authorization issue affecting command execution authorization
Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, …
CVE-2026-77105High· 8.8CommServe contained a cryptographic signature verification issue affecting privilege management
CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
CVE-2026-77104High· 7.5CommServe contained a path traversal issue affecting information disclosure
CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
CVE-2026-77103High· 7.5CommServe contained an authentication bypass issue affecting access authorization and information disclosure
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
CVE-2026-77102High· 7.5CommServe contained a heap-based buffer overflow issue affecting service availability
CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
CVE-2026-77101High· 7.5CommServe contained a stack-based buffer overflow issue affecting service availability
CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
CVE-2026-77098Critical· 9.8Private Metrics Server contained an SQL injection condition affecting database operations
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
CVE-2026-77097High· 8.2Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability
Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
CVE-2026-77092Critical· 9.8⚖ disputedContent Extractor contained a deserialization of untrusted data issue affecting privilege management
Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.
CVE-2026-77091High· 7.8DataCube contained a path traversal issue affecting security feature enforcement
DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.
CVE-2026-77089Critical· 9.8Command Center API contained an authentication bypass issue affecting privilege management
Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
CVE-2026-13738Critical· 9.8CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Web…
CVE-2026-13739Critical· 9.8A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Comm…
CVE-2026-13737Critical· 9.8CommServe contained an allowlist bypass vulnerability affecting command execution authorization
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Cen…