Skip to content
VulniPulse

Commvault Security Advisories & CVEs

8 advisories tracked · Commvault Cloud Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Commvault CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Commvault device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Commvault's recent advisories.

Official source

Commvault Cloud Security Advisories

Polled by parsing the official Commvault security-advisories index (documentation.commvault.com), which lists every CV_YYYY_MM_N advisory with its CVEs and dates. Advisory pages are fetched for new items to extract severity, impacted products and the Feature Release / Maintenance Release fix table.

Latest Commvault advisories

Critical9.2Commvault

Critical [CVE-2026-13738] Improper Authorization Validation

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customer upgrade to resolved maintenance release.CVSS score: 9.2 Commvault Software To view version support lifecyle, see Commvault software releases, release types, and release tracks. Versions not listed are out of support or unaffected. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.46.0 - 11.46.9 11.46.10 and above Resolved Commvault Linux, Windows 11.44.0 - 11.44.10 11.44.11 and above Resolved Commvault Linux, Windows 11.40.0 - 11.40.62 11.40.63 and above Resolved Commvault Linux, Windows 11.36.0 - 11.36.113 11.36.114 and above Resolved Affected product named by the advisory: Commvault Cloud.

CVE-2026-13738
Commvault Cloud (Metallic)
Aug 11, 2026
Critical9.2Commvault

Critical [CVE-2026-13737] Command Restriction Bypass

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release.CVSS score: 9.2 Commvault Software To view version support lifecyle, see Commvault software releases, release types, and release tracks. Versions not listed are out of support or unaffected. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.46.0 - 11.46.9 11.46.10 and above Resolved Commvault Linux, Windows 11.44.0 - 11.44.10 11.44.11 and above Resolved Commvault Linux, Windows 11.40.0 - 11.40.62 11.40.63 and above Resolved Commvault Linux, Windows 11.36.0 - 11.36.113 11.36.114 and above Resolved Affected product named by the advisory: Commvault Cloud.

CVE-2026-13737
Commvault Cloud (Metallic)
Aug 11, 2026
CriticalCommvault Exploited CISA KEV

Critical [CVE-2025-34028] Vulnerability in Commvault Command Center Installation

Vulnerability in Commvault Command Center Installation

CVE-2025-34028
Web Server / Command Center
May 7, 2025
CriticalCommvault

Critical SQL Injection and Command Injection Advisory

SQL Injection and Command Injection Advisory

Unclassified
Sep 16, 2024
CriticalCommvault Exploited CISA KEV

Critical [CVE-2023-46604] Remote Code Execution Vulnerability in Apache ActiveMQ

Remote Code Execution Vulnerability in Apache ActiveMQ

CVE-2023-46604
Unclassified
Nov 6, 2023
CriticalCommvault Exploited CISA KEV

Critical [CVE-2023-4863] Libwebp Vulnerability

CVE.Org link: CVE-2023-4863 Save as PDF

CVE-2023-4863
Unclassified
Oct 4, 2023
CriticalCommvault

Critical Volt Typhoon Advisory

Save as PDF Impacted Products With the recent announcement of the Volt Typhoon cyber campaign, our team has conducted a thorough security assessment of Commvault and Commvault Cloud services and have found no impact to the security, privacy, or integrity of your data backups. Resolution We also recommend you to check your Commvault and Commvault Cloud environment to ensure security controls such as the following are active:MFA is properly configured and up to dateDual authorization workflows are in place for backup and restore operationsCompliance locks are enabled for services, apps, and backup destinationsAdditionally, for customers looking for an extra layer of protection, we encourage you to evaluate ThreatWise, capable of surfacing zero-day and unknown threats in production environments. On this page

Commvault Cloud (Metallic)
May 26, 2023
CriticalCommvault Exploited CISA KEV

Critical [CVE-2021-4104 +4] Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products

CVE-2021-4104CVE-2021-44228CVE-2021-44832+2
Unclassified
Feb 1, 2022

← All vendors