Executive brief
Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells on the host system. The vulnerability affects both Windows and Linux platforms and has been observed being exploited in the wild.
Affected products
- Commvault Web Server Fixed in 11.36.46, 11.32.89, 11.28.141, 11.20.217
Timeline
- 2025-03-07: disclosed: Vendor advisory published
- 2025-04-28: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) Catalog
- 2025-04-28: advisory: NVD publication date
- 2025-04-28: exploited: Confirmed exploitation in the wild per CISA KEV entry