CVE-2026-13739: Commvault

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.

Affected products

  • Commvault Commvault: from 11.36.0, before 11.36.114 (fixed in 11.36.114); from 11.40.0, before 11.40.63 (fixed in 11.40.63); from 11.44.0, before 11.44.11 (fixed in 11.44.11); from 11.46.0, before 11.46.10 (fixed in 11.46.10)

Published 2026-08-11. Last modified 2026-09-09.