Junglewise Threat Intelligence

CVE-2026-77102: Commvault CommServe heap buffer overflow

CVE-2026-77102 · Severity: high · CVSS 7.5 · Published 2026-09-08

Technologies: Commvault CommServe. Vendors: Commvault.

Executive brief

CommServe is a core backup and disaster recovery management service used by enterprises to protect critical data. A heap-based buffer overflow in this component can cause the service to crash, resulting in temporary unavailability of backup and recovery operations for all managed systems.

Technical details

A heap-based buffer overflow vulnerability exists in CommServe, the central management and coordination service in Commvault's backup platform. The vulnerability is reachable over the network and can be triggered without prior authentication. Exploitation causes a denial of service through service crash. Affected versions include CommServe 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, and 11.46.0–11.46.19. Patches are available in maintenance releases 11.36.123 and higher, 11.40.72 and higher, 11.44.20 and higher, and 11.46.20 and higher respectively.

Affected products

  • Commvault CommServe 11.36.0-11.36.122, 11.40.0-11.40.71, 11.44.0-11.44.19, 11.46.0-11.46.19

Timeline

  • 2026-09-08: disclosed

References

Related threats