ZeroHour

CVE-2026-77101

large

Stack-based buffer overflow in Commvault CommServe causes service disruption

CVSS 4.0
8.7 high
EPSS
<1%p19
Published
()
Modified
AI analysis

Commvault CommServe contains a stack-based buffer overflow (CWE-121) that is reachable over the network without authentication or user interaction, according to the CVSS 4.0 vector. Successful triggering of the flaw crashes or disrupts the CommServe service, producing a high impact on availability; confidentiality and integrity are not affected, so the primary gain for an attacker is denial of service against the customer's backup and data-management control plane. CommServe is the central management server in Commvault deployments, so any organization running an affected build is exposed, and an outage could stall backup, restore, and scheduling operations across the estate. As of now there is no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS places 30-day exploitation probability at roughly 0.3% (17th percentile). The vendor states the issue is resolved in a maintenance release and directs customers to update CommServe.

What to do: Upgrade CommServe to the maintenance release identified by Commvault as containing the fix, since the advisory does not name a specific version. Until patched, restrict network access to the CommServe service to trusted management networks and monitor for service crashes or restarts. Because there are no public PoCs or known exploitation, prioritize this update within normal patching cycles rather than as an emergency.

Affected
Commvault CommServe
Estimated exposure
large≈ tens of thousands of CommServe deployments (typically one per enterprise Commvault installation) — Commvault is a widely deployed enterprise backup vendor with a customer base measured in the tens of thousands, and each deployment normally runs a single CommServe server, implying an order of magnitude of 10k–100k affected systems even…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.

Vendors
commvault
Products
commvault
Weakness
CWE-121
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.