Complete feed
Security advisories & CVEs
4 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-13739] Server-Side Request Forgery (SSRF)
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs.Software customers upgrade to resolved maintenance release.CVSS score: 8.8 Commvault Software To view version support lifecyle, see Commvault software releases, release types, and release tracks. Versions not listed are out of support or unaffected. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.46.0 - 11.46.9 11.46.10 and above Resolved Commvault Linux, Windows 11.44.0 - 11.44.10 11.44.11 and above Resolved Commvault Linux, Windows 11.40.0 - 11.40.62 11.40.63 and above Resolved Commvault Linux, Windows 11.36.0 - 11.36.113 11.36.114 and above Resolved Affected product named by the advisory: Commvault Cloud.
High [CVE-2025-57790] Path Traversal Vulnerability
A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to remote code execution.CVSS Score: 8.7 High Commvault Software The following versions are impacted. Versions that are not listed are either out of support or unaffected. To view version support lifecyle, see Platform Release Schedule and Lifecycles. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.32.0 - 11.32.101 11.32.102 Resolved Commvault Linux, Windows 11.36.0 - 11.36.59 11.36.60 Resolved
High [CVE-2025-3928] Critical Webserver Vulnerability
CVE.Org link: CVE-2025-3928 Save as PDF A vulnerability has been identified and remediated in all supported versions of the Commvault software. Webservers can be compromised through bad actors creating and executing webshells. Exploiting this vulnerability requires a bad actor to have authenticated user credentials within the Commvault Software environment. Unauthenticated access is not exploitable. For software customers, this means your environment must be: (i) accessible via the internet, (ii) compromised through an unrelated avenue, and (iii) accessed leveraging legitimate user credentials.
High [CVE-2021-4034] Local Privilege Escalation Vulnerability in Polkit's pkexec Utility
Local Privilege Escalation Vulnerability in Polkit's pkexec Utility