logo

CVE-2025-34028

ID: 2bf46a44-b15e-506e-8c2b-8c5db4e9611a

STIX ID: report--2bf46a44-b15e-506e-8c2b-8c5db4e9611a

Feed Name: Arctic Wolf Blog

Threat Score
78/100

Date Published: 2025-04-24

Date Updated: 2026-04-27

...
...

Arctic Wolf reports on CVE-2025-34028, a critical pre-authentication SSRF in Commvault Command Center's deployWebpackage.do endpoint that can be escalated to remote code execution using a malicious ZIP with a JSP; a public PoC exists. The bulletin lists affected and fixed versions (upgrade to 11.38.20), warns that public-facing instances should be removed from the internet, and urges organizations to patch and follow firewall/hardening guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.