Junglewise Threat Intelligence

CVE-2025-3928: Commvault Web Server Unspecified Vulnerability

CVE-2025-3928 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-04-28

Vendors: Commvault.

Executive brief

Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells on the host system. The vulnerability affects both Windows and Linux platforms and has been observed being exploited in the wild.

Affected products

  • Commvault Web Server Fixed in 11.36.46, 11.32.89, 11.28.141, 11.20.217

Timeline

  • 2025-03-07: disclosed: Vendor advisory published
  • 2025-04-28: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) Catalog
  • 2025-04-28: advisory: NVD publication date
  • 2025-04-28: exploited: Confirmed exploitation in the wild per CISA KEV entry

Related threats