Skip to content
VulniPulse

Commvault Security Advisories & CVEs

4 advisories tracked · Commvault Cloud Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Commvault CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Commvault device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Commvault's recent advisories.

Official source

Commvault Cloud Security Advisories

Polled by parsing the official Commvault security-advisories index (documentation.commvault.com), which lists every CV_YYYY_MM_N advisory with its CVEs and dates. Advisory pages are fetched for new items to extract severity, impacted products and the Feature Release / Maintenance Release fix table.

Latest Commvault advisories

High8.8Commvault

High [CVE-2026-13739] Server-Side Request Forgery (SSRF)

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs.Software customers upgrade to resolved maintenance release.CVSS score: 8.8 Commvault Software To view version support lifecyle, see Commvault software releases, release types, and release tracks. Versions not listed are out of support or unaffected. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.46.0 - 11.46.9 11.46.10 and above Resolved Commvault Linux, Windows 11.44.0 - 11.44.10 11.44.11 and above Resolved Commvault Linux, Windows 11.40.0 - 11.40.62 11.40.63 and above Resolved Commvault Linux, Windows 11.36.0 - 11.36.113 11.36.114 and above Resolved Affected product named by the advisory: Commvault Cloud.

CVE-2026-13739
Commvault Cloud (Metallic)
Aug 11, 2026
High8.7Commvault

High [CVE-2025-57790] Path Traversal Vulnerability

A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to remote code execution.CVSS Score: 8.7 High Commvault Software The following versions are impacted. Versions that are not listed are either out of support or unaffected. To view version support lifecyle, see Platform Release Schedule and Lifecycles. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.32.0 - 11.32.101 11.32.102 Resolved Commvault Linux, Windows 11.36.0 - 11.36.59 11.36.60 Resolved

CVE-2025-57790
Unclassified
Sep 3, 2025
HighCommvault Exploited CISA KEV

High [CVE-2025-3928] Critical Webserver Vulnerability

CVE.Org link: CVE-2025-3928 Save as PDF A vulnerability has been identified and remediated in all supported versions of the Commvault software. Webservers can be compromised through bad actors creating and executing webshells. Exploiting this vulnerability requires a bad actor to have authenticated user credentials within the Commvault Software environment. Unauthenticated access is not exploitable. For software customers, this means your environment must be: (i) accessible via the internet, (ii) compromised through an unrelated avenue, and (iii) accessed leveraging legitimate user credentials.

CVE-2025-3928
Unclassified
May 1, 2025
HighCommvault Exploited CISA KEV

High [CVE-2021-4034] Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

CVE-2021-4034
Unclassified
Jan 29, 2022

← All vendors