logo

Researcher Says Patched Commvault Bug Still Exploitable

ID: c3469da1-c08a-5d8b-b458-f50697dde79a

STIX ID: report--c3469da1-c08a-5d8b-b458-f50697dde79a

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-05-06

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

**A critical pre-auth SSRF (CVE-2025-34028) in Commvault Command Center enables unauthenticated remote code execution; researchers and CISA report active exploitation and proof-of-concept code that appears to bypass fixes in versions 11.38.20 and 11.38.25, exposing widespread backup infrastructure to compromise.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.