U.S. CISA adds Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-1976 | Admin-to-Root Privilege Escalation in Broadcom Brocade Fabric OS 9.1 CVE-2025-1976 is a code/command injection flaw (CWE-94, CWE-78) in Broadcom Brocade Fabric OS, the operating system running on Brocade fibre-channel SAN switches. Starting with Fabric OS 9.1.0, root access was removed from administrators, but on versions 9.1.0 through 9.1.1d6 a local user with admin privileges can inject and execute arbitrary code to run with full root privileges. The CVSS 4.0 vector (AV:A/PR:L) indicates the attacker needs adjacent access with admin-level credentials and no user interaction, and successful exploitation grants complete root control of the switch, potentially compromising SAN fabric operations and enabling persistence in the storage network. Any organization running Brocade switches on the affected Fabric OS 9.1.0–9.1.1d6 range is exposed. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, confirming active exploitation; no public PoC is known and EPSS puts 30-day exploitation probability at 0.7%. Do: Upgrade Brocade Fabric OS to a release later than 9.1.1d6 following Brocade's security advisory; because the affected range ends at 9.1.1d6, any switch on 9.1.0–9.1.1d6 should be treated as vulnerable. Until patched, restrict admin CLI/SSH/API access to trusted administrators, audit admin accounts and CLI logs for signs of misuse, and hunt for unexpected code execution on switches. U.S. federal agencies must apply vendor mitigations or discontinue use per BOD 22-01 timelines, given the KEV listing. | 8.6 | <1% | KEV |
| moderatelikely on the order of thousands to tens of thousands of SAN switches running FOS 9.1.0–9.1.1d6; exact counts unknown | |
| CVE-2025-3928 | Actively Exploited Authenticated Webshell Flaw in Commvault Web Server CVE-2025-3928 is an unspecified vulnerability in the Commvault Web Server, the web administration component of Commvault's data protection platform, which can be exploited over the network by a remote attacker who holds valid (low-privilege) authenticated access. According to the Commvault advisory, attackers use the flaw to create and execute webshells on the web server, and the CVSS 4.0 score of 8.7 (High) reflects high impact to the confidentiality, integrity, and availability of the vulnerable web server component. It affects Commvault Web Server on both Windows and Linux across the supported release streams, with fixes delivered in 11.36.46, 11.32.89, 11.28.141, and 11.20.217. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, and Commvault has confirmed that hackers exploited it in the wild as a zero-day, with related reporting noting heightened Silk Typhoon (Chinese nation-state) attack activity. No public proof-of-concept is known, but the confirmed real-world zero-day exploitation makes patching urgent. Do: Upgrade the Commvault Web Server to 11.36.46, 11.32.89, 11.28.141, or 11.20.217, matching your current release stream, on both Windows and Linux platforms. Because the flaw was exploited as a zero-day, hunt for attacker-created webshells and unexpected accounts, scripts, or scheduled tasks on Commvault web server hosts, review authentication logs for suspicious logins, and restrict the Commvault web interface to trusted networks. Federal agencies must apply vendor mitigations per CISA instructions or follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. | 8.7 | 2% | KEV |
| large≈ tens of thousands of enterprise deployments worldwide (one Web Server per Commvault environment); internet-exposed instances likely in the thousands | |
| CVE-2025-42599 | Unauthenticated RCE via Stack-Based Buffer Overflow in Qualitia Active! mail 6 Qualitia Active! mail 6 (BuildInfo 6.60.05008561 and earlier) contains a stack-based buffer overflow (CWE-121) that is triggered when the webmail server processes a single specially crafted network request, with no authentication or user interaction required. A remote unauthenticated attacker who sends such a request can execute arbitrary code on the server or crash the service, causing a denial-of-service condition. With a CVSS 3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N, high impact on confidentiality, integrity, and availability), any internet-exposed deployment is at critical risk; the product is a webmail platform widely deployed by Japanese enterprises, universities, and government organizations. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use has not been reported. Organizations running affected builds should treat their webmail servers as likely targets and patch per vendor guidance immediately. Do: Upgrade Active! mail 6 to a BuildInfo later than 6.60.05008561, following Qualitia's advisory (JPCERT is the assigning CNA, so its alert should be used as the authoritative update reference). Until patched, restrict internet access to the webmail interface via IP allow-listing or VPN and review server logs for exploitation attempts, since in-the-wild exploitation is confirmed. US federal agencies must apply the required mitigations per vendor instructions and BOD 22-01 timelines, or discontinue use of the product if mitigations are unavailable. | 9.8 | 3% | KEV |
| largelikely on the order of 100,000+ users (mailboxes) across a thousand-plus Japanese organizations, with thousands of internet-exposed webmail servers |
Full article315 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the descriptions for these flaws:
- CVE-2025-1976 Broadcom Brocade Fabric OS Code Injection Vulnerability – In Brocade Fabric OS versions 9.1.0 to 9.1.1d6, although direct root access was officially removed, a local user with administrative privileges can still exploit a vulnerability to execute arbitrary code with full root privileges. This flaw effectively bypasses the intended security restrictions, allowing complete control over the system.
- CVE-2025-42599 is a Stack-Based Buffer Overflow Vulnerability in Qualitia Active! Mail. The flaw impacts Active! mail 6 BuildInfo: 6.60.05008561 and earlier. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.
- CVE-2025-3928 Commvault Web Server Unspecified Vulnerability. Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: “Webservers can be compromised through bad actors creating and executing webshells.” Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities CVE-2025-1976 and CVE-2025-42599 by May 19, 2025. CISA orders federal agencies to fix the vulnerability CVE-2025-3928 by May 17, 2025.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/177161/hacking/u-s-cisa-adds-qualitia-active-mail-broadcom-brocade-fabric-os-and-commvault-web-server-flaws-to-its-known-exploited-vulnerabilities-catalog.html