CVE-2025-3928
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-3928 is a recently disclosed vulnerability affecting Commvault Web Server. Authenticated attackers can exploit this unspecified issue to compromise webservers by creating and executing webshells. The vulnerability has been addressed in versions 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for both Windows and Linux platforms. On April 28, 2025, it was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog, indicating that it is currently being exploited in the wild. Organizations using affected versions should update as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.