peter bassill · operator
$ cve CVE-2025-3928 JSON

CVE-2025-3928 KEV

8.8
HIGH · CVSS 3.1 · EPSS 2.3% (pctl 83)

Patch first

On CISA KEV — known exploited in the wild, due 2025-05-19.

Description

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS2.3% — more likely to be exploited than 83% of all CVEs
On CISA KEVyes — remediate by 2025-05-19
Public exploitnone known
Published2025-04-25
Last modified2026-06-17

CISA KEV

NameCommvault Web Server Unspecified Vulnerability
Added2025-04-28
Due2025-05-19
Vendor / productCommvault / Web Server
Ransomware usenone reported

Affected (3)

VendorProduct
commvaultcommvault
linuxlinux kernel
microsoftwindows

References

→ the Explorer  ·  watch your stack  ·  NVD