CVE-2026-13739: Commvault
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.
Affected products
- Commvault Commvault: from 11.36.0, before 11.36.114 (fixed in 11.36.114); from 11.40.0, before 11.40.63 (fixed in 11.40.63); from 11.44.0, before 11.44.11 (fixed in 11.44.11); from 11.46.0, before 11.46.10 (fixed in 11.46.10)
Published 2026-08-11. Last modified 2026-09-09.