Max-Severity Commvault Bug Alarms Researchers
ID: 5129e243-046e-5712-8c85-fb48f428e4bd
STIX ID: report--5129e243-046e-5712-8c85-fb48f428e4bd
Feed Name: Dark Reading
Threat Score
**Executive Summary:** CVE-2025-34028 is a critical pre-authenticated SSRF in Commvault Command Center (Windows/Linux, 11.38.0–11.38.19) that can lead to remote code execution via a ZIP-based chained attack delivering a web shell; watchTowr published a proof-of-concept and Commvault released fixes in 11.38.20/11.38.25 (auto-deployed), with guidance to immediately apply patches, verify update connectivity, and isolate management interfaces until remediation is confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
