High severity8.8CISA KEVNVD Advisory· Published Apr 25, 2025· Updated Jun 17, 2026
CVE-2025-3928
CVE-2025-3928
Description
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: before 11.36.46, 11.32.89, 11.28.141, and 11.20.217
- Commvault/Web Serverv5Range: 11.36.0
Patches
Vulnerability mechanics
References
8- documentation.commvault.com/securityadvisories/CV_2025_03_1.htmlnvdVendor Advisory
- www.bleepingcomputer.com/news/security/commvault-says-recent-breach-didnt-impact-customer-backup-data/nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdThird Party AdvisoryUS Government Resource
- www.cisa.gov/news-events/alerts/2025/05/22/advisory-update-cyber-threat-activity-targeting-commvaults-saas-cloud-application-metallicnvdThird Party AdvisoryUS Government Resource
- www.commvault.com/blogs/customer-security-updatenvdVendor Advisory
- www.commvault.com/blogs/notice-security-advisory-updatenvdVendor Advisory
- www.commvault.com/blogs/security-advisory-march-7-2025nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.