Vulnerability Intelligence Report
Commvault Web Server unspecified vulnerability
CVE-2025-3928
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:1.87%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Commvault | Web Server | 11.36.0 < 11.36.46 (affected), 11.36.46 (unaffected), 11.32.0 < 11.32.89 (affected), 11.32.89 (unaffected), 11.28.0 < 11.28.141 (affected), 11.28.141 (unaffected), 11.20.0 < 11.20.217 (affected), 11.20.217 (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government · CERT · USA |
| Reserved | 2025-04-24T19:55:32 |
| Published | 2025-04-25T15:56:28 |
| Patch Date | 2025-02-24 |
| Last Updated | 2026-02-26T18:28:03 |
Community Chatter & Buzz