ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Commvault Confirms Hackers Exploited CVE-2025-3928 as Zero

criticalVulnerability exploited in the wildimportance 60CVE-2025-3928

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-3928
Actively Exploited Authenticated Webshell Flaw in Commvault Web Server

CVE-2025-3928 is an unspecified vulnerability in the Commvault Web Server, the web administration component of Commvault's data protection platform, which can be exploited over the network by a remote attacker who holds valid (low-privilege) authenticated access. According to the Commvault advisory, attackers use the flaw to create and execute webshells on the web server, and the CVSS 4.0 score of 8.7 (High) reflects high impact to the confidentiality, integrity, and availability of the vulnerable web server component. It affects Commvault Web Server on both Windows and Linux across the supported release streams, with fixes delivered in 11.36.46, 11.32.89, 11.28.141, and 11.20.217. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, and Commvault has confirmed that hackers exploited it in the wild as a zero-day, with related reporting noting heightened Silk Typhoon (Chinese nation-state) attack activity. No public proof-of-concept is known, but the confirmed real-world zero-day exploitation makes patching urgent.

Do: Upgrade the Commvault Web Server to 11.36.46, 11.32.89, 11.28.141, or 11.20.217, matching your current release stream, on both Windows and Linux platforms. Because the flaw was exploited as a zero-day, hunt for attacker-created webshells and unexpected accounts, scripts, or scheduled tasks on Commvault web server hosts, review authentication logs for suspicious logins, and restrict the Commvault web interface to trusted networks. Federal agencies must apply vendor mitigations per CISA instructions or follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.

8.72% KEV
  • Commvault Web Server Commvault Web Server on Windows and Linux, versions prior to the fixes in each supported release stream: 11.36 before 11.36.46, 11.32 before 11.32.89, 11.28 bef
large≈ tens of thousands of enterprise deployments worldwide (one Web Server per Commvault environment); internet-exposed instances likely in the thousands

Indicators of compromiseAll →

TypeIndicatorContext
ipv4108.69.148.100IP addresses have been associated with malicious activity - 108.69.148.100 128.92.80.210 184.153.42.129 108.6.189.53, and 159.242.42.2
ipv4128.92.80.210ve been associated with malicious activity - 108.69.148.100 128.92.80.210 184.153.42.129 108.6.189.53, and 159.242.42.20 "These IP ad
ipv4184.153.42.129ated with malicious activity - 108.69.148.100 128.92.80.210 184.153.42.129 108.6.189.53, and 159.242.42.20 "These IP addresses should
Full article340 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMay 01, 2025Zero-Day / Threat Intelligence

Enterprise data backup platform Commvault has revealed that an unknown nation-state threat actor breached its Microsoft Azure environment by exploiting CVE-2025-3928 but emphasized there is no evidence of unauthorized data access.

"This activity has affected a small number of customers we have in common with Microsoft, and we are working with those customers to provide assistance," the company said in an update.

"Importantly, there has been no unauthorized access to customer backup data that Commvault stores and protects, and no material impact on our business operations or our ability to deliver products and services."

In an advisory issued on March 7, 2025, Commvault said it was notified by Microsoft on February 20 about unauthorized activity within its Azure environment and that the threat actor exploited CVE-2025-3928 as a zero-day. It also said it rotated affected credentials and enhanced security measures.

The disclosure comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-3928 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary patches for Commvault Web Server by May 19, 2025.

To mitigate the risk posed by such attacks, customers are advised to apply a Conditional Access policy to all Microsoft 365, Dynamics 365, and Azure AD single-tenant app registrations, and rotate and sync client secrets between Azure portal and Commvault every 90 days.

The company is also urging users to monitor sign-in activity to detect any access attempts originating from IP addresses outside of the allowlisted ranges. The following IP addresses have been associated with malicious activity -

  • 108.69.148.100
  • 128.92.80.210
  • 184.153.42.129
  • 108.6.189.53, and
  • 159.242.42.20

"These IP addresses should be explicitly blocked within your Conditional Access policies and monitored in your Azure sign-in logs," Commvault said. "If any access attempts from these IPs are detected, please report the incident immediately to Commvault Support for further analysis and action."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/05/commvault-confirms-hackers-exploited.html