CVE-2026-77098: Commvault
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.
Affected products
- Commvault Commvault: from 11.36.0, before 11.36.123 (fixed in 11.36.123); from 11.40.0, before 11.40.72 (fixed in 11.40.72); from 11.44.0, before 11.44.20 (fixed in 11.44.20); from 11.46.0, before 11.46.20 (fixed in 11.46.20)
Published 2026-09-08. Last modified 2026-09-11.