CVE-2026-77102
largeHeap-Based Buffer Overflow in Commvault CommServe Enables Remote DoS
CVE-2026-77102 is a heap-based buffer overflow (CWE-122) in the CommServe component of Commvault's data protection software. Per the CVSS 4.0 vector, the flaw is reachable over the network and can be triggered without authentication, without user interaction, and without special conditions. A remote attacker who sends crafted input to the affected service can corrupt heap memory and crash the CommServe process, producing a high impact on service availability but no direct loss of confidentiality or integrity. Organizations running affected CommServe maintenance releases are impacted, and the vendor has shipped a resolved maintenance release with instructions for customers to update CommServe. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Upgrade CommServe to the maintenance release designated by Commvault's advisory for CVE-2026-77102 (apply the vendor's current maintenance roll-up, since specific fixed version numbers are not stated here). Until patched, restrict network access to the CommServe host so unauthenticated clients and untrusted network segments cannot reach the vulnerable service. Monitor CommServe service health and restart events, as exploitation manifests as an availability-affecting crash rather than data compromise.
| Commvault CommServe (central management server component of Commvault data protection software) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
- Vendors
- commvault
- Products
- commvault
- Weakness
- CWE-122
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.