logo

Max-Severity Commvault Bug Alarms Researchers

ID: 5129e243-046e-5712-8c85-fb48f428e4bd

STIX ID: report--5129e243-046e-5712-8c85-fb48f428e4bd

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2025-04-24

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

**Executive Summary:** CVE-2025-34028 is a critical pre-authenticated SSRF in Commvault Command Center (Windows/Linux, 11.38.0–11.38.19) that can lead to remote code execution via a ZIP-based chained attack delivering a web shell; watchTowr published a proof-of-concept and Commvault released fixes in 11.38.20/11.38.25 (auto-deployed), with guidance to immediately apply patches, verify update connectivity, and isolate management interfaces until remediation is confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.