ZeroHour

CVE-2025-3928

KEVlarge

Actively Exploited Authenticated Webshell Flaw in Commvault Web Server

CISA: Commvault Web Server Unspecified Vulnerability

CVSS 4.0
8.7 high
EPSS
2%p81
Published
()
KEV added
AI analysis

CVE-2025-3928 is an unspecified vulnerability in the Commvault Web Server, the web administration component of Commvault's data protection platform, which can be exploited over the network by a remote attacker who holds valid (low-privilege) authenticated access. According to the Commvault advisory, attackers use the flaw to create and execute webshells on the web server, and the CVSS 4.0 score of 8.7 (High) reflects high impact to the confidentiality, integrity, and availability of the vulnerable web server component. It affects Commvault Web Server on both Windows and Linux across the supported release streams, with fixes delivered in 11.36.46, 11.32.89, 11.28.141, and 11.20.217. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, and Commvault has confirmed that hackers exploited it in the wild as a zero-day, with related reporting noting heightened Silk Typhoon (Chinese nation-state) attack activity. No public proof-of-concept is known, but the confirmed real-world zero-day exploitation makes patching urgent.

What to do: Upgrade the Commvault Web Server to 11.36.46, 11.32.89, 11.28.141, or 11.20.217, matching your current release stream, on both Windows and Linux platforms. Because the flaw was exploited as a zero-day, hunt for attacker-created webshells and unexpected accounts, scripts, or scheduled tasks on Commvault web server hosts, review authentication logs for suspicious logins, and restrict the Commvault web interface to trusted networks. Federal agencies must apply vendor mitigations per CISA instructions or follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.

Affected
Commvault Web ServerCommvault Web Server on Windows and Linux, versions prior to the fixes in each supported release stream: 11.36 before 11.36.46, 11.32 before 11.32.89, 11.28 bef
Estimated exposure
large≈ tens of thousands of enterprise deployments worldwide (one Web Server per Commvault environment); internet-exposed instances likely in the thousands — No install counts or internet-scan data were provided, so this is an order-of-magnitude estimate based on Commvault's position as a widely deployed enterprise backup platform, where nearly every customer environment running supported 11.x…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.

CISA Known Exploited Vulnerability
Affected
Commvault Web Server
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
commvault
Products
commvault
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news