CVE-2025-3928

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 25, 2025
Updated: May 6, 2025

Summary

CVE-2025-3928 is a recently disclosed vulnerability affecting Commvault Web Server. Authenticated attackers can exploit this unspecified issue to compromise webservers by creating and executing webshells. The vulnerability has been addressed in versions 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for both Windows and Linux platforms. On April 28, 2025, it was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog, indicating that it is currently being exploited in the wild. Organizations using affected versions should update as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share