CVE-2025-3928: Commvault Web Server Unspecified Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-04-28. EPSS: 2.5% chance of exploitation in the next 30 days.

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.

Affected products

  • Commvault Commvault: from 11.20.0, before 11.20.217 (fixed in 11.20.217); from 11.28.0, before 11.28.141 (fixed in 11.28.141); from 11.32.0, before 11.32.89 (fixed in 11.32.89); from 11.36.0, before 11.36.46 (fixed in 11.36.46)

Published 2025-04-25. Last modified 2026-10-08.