CISA warns about actively exploited Broadcom, Commvault vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-1976 | Admin-to-Root Privilege Escalation in Broadcom Brocade Fabric OS 9.1 CVE-2025-1976 is a code/command injection flaw (CWE-94, CWE-78) in Broadcom Brocade Fabric OS, the operating system running on Brocade fibre-channel SAN switches. Starting with Fabric OS 9.1.0, root access was removed from administrators, but on versions 9.1.0 through 9.1.1d6 a local user with admin privileges can inject and execute arbitrary code to run with full root privileges. The CVSS 4.0 vector (AV:A/PR:L) indicates the attacker needs adjacent access with admin-level credentials and no user interaction, and successful exploitation grants complete root control of the switch, potentially compromising SAN fabric operations and enabling persistence in the storage network. Any organization running Brocade switches on the affected Fabric OS 9.1.0–9.1.1d6 range is exposed. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, confirming active exploitation; no public PoC is known and EPSS puts 30-day exploitation probability at 0.7%. Do: Upgrade Brocade Fabric OS to a release later than 9.1.1d6 following Brocade's security advisory; because the affected range ends at 9.1.1d6, any switch on 9.1.0–9.1.1d6 should be treated as vulnerable. Until patched, restrict admin CLI/SSH/API access to trusted administrators, audit admin accounts and CLI logs for signs of misuse, and hunt for unexpected code execution on switches. U.S. federal agencies must apply vendor mitigations or discontinue use per BOD 22-01 timelines, given the KEV listing. | 8.6 | <1% | KEV |
| moderatelikely on the order of thousands to tens of thousands of SAN switches running FOS 9.1.0–9.1.1d6; exact counts unknown | |
| CVE-2025-3928 | Actively Exploited Authenticated Webshell Flaw in Commvault Web Server CVE-2025-3928 is an unspecified vulnerability in the Commvault Web Server, the web administration component of Commvault's data protection platform, which can be exploited over the network by a remote attacker who holds valid (low-privilege) authenticated access. According to the Commvault advisory, attackers use the flaw to create and execute webshells on the web server, and the CVSS 4.0 score of 8.7 (High) reflects high impact to the confidentiality, integrity, and availability of the vulnerable web server component. It affects Commvault Web Server on both Windows and Linux across the supported release streams, with fixes delivered in 11.36.46, 11.32.89, 11.28.141, and 11.20.217. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, and Commvault has confirmed that hackers exploited it in the wild as a zero-day, with related reporting noting heightened Silk Typhoon (Chinese nation-state) attack activity. No public proof-of-concept is known, but the confirmed real-world zero-day exploitation makes patching urgent. Do: Upgrade the Commvault Web Server to 11.36.46, 11.32.89, 11.28.141, or 11.20.217, matching your current release stream, on both Windows and Linux platforms. Because the flaw was exploited as a zero-day, hunt for attacker-created webshells and unexpected accounts, scripts, or scheduled tasks on Commvault web server hosts, review authentication logs for suspicious logins, and restrict the Commvault web interface to trusted networks. Federal agencies must apply vendor mitigations per CISA instructions or follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. | 8.7 | 2% | KEV |
| large≈ tens of thousands of enterprise deployments worldwide (one Web Server per Commvault environment); internet-exposed instances likely in the thousands | |
| CVE-2025-42599 | Unauthenticated RCE via Stack-Based Buffer Overflow in Qualitia Active! mail 6 Qualitia Active! mail 6 (BuildInfo 6.60.05008561 and earlier) contains a stack-based buffer overflow (CWE-121) that is triggered when the webmail server processes a single specially crafted network request, with no authentication or user interaction required. A remote unauthenticated attacker who sends such a request can execute arbitrary code on the server or crash the service, causing a denial-of-service condition. With a CVSS 3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N, high impact on confidentiality, integrity, and availability), any internet-exposed deployment is at critical risk; the product is a webmail platform widely deployed by Japanese enterprises, universities, and government organizations. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use has not been reported. Organizations running affected builds should treat their webmail servers as likely targets and patch per vendor guidance immediately. Do: Upgrade Active! mail 6 to a BuildInfo later than 6.60.05008561, following Qualitia's advisory (JPCERT is the assigning CNA, so its alert should be used as the authoritative update reference). Until patched, restrict internet access to the webmail interface via IP allow-listing or VPN and review server logs for exploitation attempts, since in-the-wild exploitation is confirmed. US federal agencies must apply the required mitigations per vendor instructions and BOD 22-01 timelines, or discontinue use of the product if mitigations are unavailable. | 9.8 | 3% | KEV |
| largelikely on the order of 100,000+ users (mailboxes) across a thousand-plus Japanese organizations, with thousands of internet-exposed webmail servers |
Full article669 words · extracted from helpnetsecurity.com · click to collapse
The Cybersecurity and Infrastructure Security Agency (CISA) has added three new flaws to its Known Exploited Vulnerabilities catalog on Monday, affecting Commvault (CVE-2025-3928), Active! Mail (CVE-2025-42599), and Broadcom Brocade (CVE-2025-1976) solutions.
CISA’s KEV catalog is constantly updated and provides IT admins in US federal civilian agencies with instructions on how to remediate these threats and by which date (as mandated by the Binding Operational Directive 22-01), but this living document can also come in handy to other organizations around the world.
Vulnerabilities exploited as zero-days
CVE-2025-3928 is an unspecified vulnerability that affected the web server module in all Commvault CommServe, Web Servers, and Command Center software. It was fixed in late February 2024, after it was spotted being exploited in zero-day attacks by a nation-state threat actor.
“Exploiting this vulnerability requires a bad actor to have authenticated user credentials within the Commvault Software environment. Unauthenticated access is not exploitable. For software customers, this means your environment must be: (i) accessible via the internet, (ii) compromised through an unrelated avenue, and (iii) accessed leveraging legitimate user credentials,” the company said.
In a recent update on the February attacks, Commvault said that only a small number of customers have been affected.
“Importantly, there has been no unauthorized access to customer backup data that Commvault stores and protects, and no material impact on our business operations or our ability to deliver products and services,” the company added. Though, it has to be noted, the investigation into the incident is not over yet.
CVE-2025-3928 has been fixed in versions 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms.
(As a side note: Commvault has recently patched a critical unauthenticated RCE flaw in Command Center vulnerability with a public PoC exploit.)
CVE-2025-42599 is a stack-based buffer overflow vulnerability in the Qualitia Active! Mail web-based email client.
It allows unauthenticated, remote attackers to achieve code execution or trigger a denial-of-service (DoS) condition by sending a specially crafted malicious request, and has been exploited by attackers in zero-day attacks to target organizations in Japan, where the solution is widely used.
Users have been advised to update to Active! Mail 6 BuildInfo: 6.60.06008562 as soon as possible.
FInally, CVE-2025-1976 is a code injection vulnerability in the Fabric OS, running on Broadcom Brocade data center networking and storage gear.
“Through a flaw in IP Address validation, a local user, assigned one of the pre-defined admin roles or a user-defined role with admin-level privileges, can execute arbitrary code as if they had full root level access,” Broadcom said in an advisory published nearly two weeks ago.
“This vulnerability can allow the user to execute any existing Fabric OS command or can also be used to modify the Fabric OS itself, including adding their own subroutines. Even though achieving this exploit first requires valid access to a role with admin privileges, this vulnerability has been actively exploited in the field.”
No additional details about the attacks have been shared. The vulnerability affects Brocade Fabric OS versions 9.1.0 through 9.1.1d6, and has been fixed in version 9.1.1d7.
“Brocade PSIRT recommends customers to upgrade to a version of Fabric OS that has removed root access for enhanced security where possible,” the company added.
UPDATE (May 23, 2025, 10:25 a.m. ET):
CISA has released an update on the attacks leveraging CVE-2025-3928.
“Commvault is monitoring cyber threat activity targeting their applications hosted in their Microsoft Azure cloud environment. Threat actors may have accessed client secrets for Commvault’s (Metallic) Microsoft 365 (M365) backup software-as-a-service (SaaS) solution, hosted in Azure. This provided the threat actors with unauthorized access to Commvault’s customers’ M365 environments that have application secrets stored by Commvault,” the agency said.
“CISA believes the threat activity may be part of a larger campaign targeting various SaaS companies’ cloud applications with default configurations and elevated permissions.”
Commvault customers are advised to implement the actions recommended by CISA and Commvault.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/04/29/cisa-warns-about-actively-exploited-broadcom-commvault-vulnerabilities-cve-2025-1976-cve-2025-3928/