ZeroHour

CVE-2026-77102

large

Heap-Based Buffer Overflow in Commvault CommServe Enables Remote DoS

CVSS 4.0
8.7 high
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-77102 is a heap-based buffer overflow (CWE-122) in the CommServe component of Commvault's data protection software. Per the CVSS 4.0 vector, the flaw is reachable over the network and can be triggered without authentication, without user interaction, and without special conditions. A remote attacker who sends crafted input to the affected service can corrupt heap memory and crash the CommServe process, producing a high impact on service availability but no direct loss of confidentiality or integrity. Organizations running affected CommServe maintenance releases are impacted, and the vendor has shipped a resolved maintenance release with instructions for customers to update CommServe. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Upgrade CommServe to the maintenance release designated by Commvault's advisory for CVE-2026-77102 (apply the vendor's current maintenance roll-up, since specific fixed version numbers are not stated here). Until patched, restrict network access to the CommServe host so unauthenticated clients and untrusted network segments cannot reach the vulnerable service. Monitor CommServe service health and restart events, as exploitation manifests as an availability-affecting crash rather than data compromise.

Affected
Commvault CommServe (central management server component of Commvault data protection software)
Estimated exposure
large≈20,000–40,000 CommServe server deployments (order of magnitude: tens of thousands) — CommServe is the central management server typically deployed once per Commvault customer environment, and Commvault's publicly reported customer base of roughly 24,000+ enterprise customers implies tens of thousands of installations, most…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.

Vendors
commvault
Products
commvault
Weakness
CWE-122
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.