CVE-2026-13737: Commvault
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Affected products
- Commvault Commvault: from 11.36.0, before 11.36.114 (fixed in 11.36.114); from 11.40.0, before 11.40.63 (fixed in 11.40.63); from 11.44.0, before 11.44.11 (fixed in 11.44.11); from 11.46.0, before 11.46.10 (fixed in 11.46.10)
Published 2026-08-11. Last modified 2026-09-09.