logo

CVE-2025-34028: PoC Released for Critical RCE Vulnerability in Commvault Command Center

ID: e576f2d1-0dc0-5dde-8191-d43bf707c9ee

STIX ID: report--e576f2d1-0dc0-5dde-8191-d43bf707c9ee

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2025-04-24

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

**Executive summary:** Arctic Wolf reports a critical Commvault Command Center vulnerability (CVE-2025-34028) disclosed with a public proof-of-concept that enables pre-authenticated SSRF leading to potential remote code execution; no active exploitation observed to date. The advisory recommends updating affected Commvault versions to 11.38.20 and removing publicly exposed Command Center instances to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.