LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-3928: Commvault Web Server Unspecified Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 28, 2025
CVSS 8.7 · High⚠ Actively exploited (CISA KEV)
8.7
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
May 19, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-3928 to its Known Exploited Vulnerabilities catalog on Apr 28, 2025, with a federal patch deadline of May 19, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.

CVE-2025-3928 is an unspecified vulnerability in the Commvault Web Server that lets a remote attacker who already has valid authentication create and execute webshells. Webshells give the attacker a persistent foothold on the server, which can be used to run further commands, move laterally, or access backup data and credentials. Because Commvault environments often hold sensitive enterprise backups, successful abuse can expand an intrusion quickly. Exact technical details and affected builds must be confirmed against the vendor advisory.

How it works

The vulnerability class is not further specified beyond the ability of a remote, authenticated attacker to create and execute webshells on the Commvault Web Server. In practice this means an attacker who has already obtained legitimate credentials (or a session) can plant a webshell—typically a small script that accepts remote commands—and then use it to maintain access even after the original session ends. Webshells commonly allow arbitrary file operations, command execution, and data exfiltration under the privileges of the web-server process. Because the flaw is described only at this high level, defenders should treat any authenticated remote code-execution path on the web tier as the attack surface and verify the precise conditions in the vendor advisory rather than assuming particular request formats or parameters.

Am I affected? How to find it in your systems

Commvault Web Server components typically run as part of on-premises or hybrid backup and recovery infrastructure, often exposed to management networks or, in some deployments, to broader internal or partner networks. Inventory all Commvault installations by querying asset-management systems, scanning for the product’s characteristic services and ports, and reviewing configuration-management databases for “Commvault” or related web-server packages. Once located, compare the installed version and configuration against the list of affected builds published in the vendor advisory; do not rely on version numbers reported elsewhere. Look for signs of exploitation in web-server access and error logs: unexpected script file creation under web-root or temporary directories, anomalous POST or authenticated requests that result in new files, or process-creation events that spawn shells or interpreters from the web-server context. Endpoint detection and response telemetry that flags webshell-like behavior (file writes followed by network callbacks or command execution) should also be reviewed for hosts running Commvault.

How to remediate

Apply the vendor-supplied update or mitigation package for the Commvault Web Server as soon as it is available and tested in your environment; this is the primary remediation. Follow the exact instructions in the vendor advisory, including any required configuration changes or service restarts. For cloud-hosted or managed Commvault instances, also follow applicable Binding Operational Directive 22-01 guidance. If the advisory indicates that mitigations are unavailable, discontinue use of the affected product until a fix can be applied. After patching, re-inventory systems to confirm the update is present and re-baseline logs and file-integrity monitoring to detect any residual webshells that may have been planted before remediation.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure by network segmentation: place the Commvault Web Server behind strict firewall rules that allow access only from trusted administrative jump hosts or management subnets. If a web application firewall is available, enable rules that detect and block common webshell upload or execution patterns, treating them as virtual patches for this class of flaw. Disable any non-essential web-server features or remote-management interfaces that are not required for operations. Increase monitoring of authentication events, file-system changes under web directories, and outbound connections from the Commvault host; alert on any unexpected script creation or process spawning. As a last resort, if mitigations cannot be implemented and the risk is unacceptable, discontinue use of the product per CISA guidance until a permanent fix is in place.

If your data may have been exposed

Vulnerabilities that permit webshell creation are frequently used to establish long-term access and can lead to data theft or further compromise of backup repositories. If you have evidence of exploitation or simply want to check whether credentials associated with your organization have appeared in known breach data, run a free exposure scan of relevant email addresses against public breach corpora. Continue internal investigation of logs and file systems for residual webshells regardless of external scan results.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCommvault · Web Server
CVSS base score8.7 (High)
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
PublishedApr 25, 2025
Added to CISA KEVApr 28, 2025
Federal patch deadlineMay 19, 2025
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities