Commvault security advisory (AV26-899)
Canadian Cyber Centre warns Commvault Cloud versions prior to 11.36.123, 11.40.72, 11.44.20, and 11.46.20 are affected by vulnerabilities; updates required.
The Canadian Centre for Cyber Security issued advisory AV26-899 stating that Commvault Cloud is affected by vulnerabilities as of September 8, 2026. Affected branches are 36.0 before 11.36.123, 40.0 before 11.40.72, 44.0 before 11.44.20, and 46.0 before 11.46.20. The advisory links to Commvault's own security advisories and urges administrators to apply available updates; no CVE identifiers, severity ratings, or exploitation details are provided.
- Commvault Cloud releases 36.0, 40.0, 44.0, and 46.0 are affected before fixed builds 11.36.123, 11.40.72, 11.44.20, and 11.46.20.
- No CVE IDs, severity scores, or exploitation details are given; administrators should review Commvault's advisories and patch.
Full article69 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-899
Date: September 9, 2026
Commvault security advisory (AV26-899)
As of September 8, 2026, Commvault is affected by vulnerabilities in the following product:
- Commvault Cloud
- 36.0 Prior to 11.36.123
- 40.0 Prior to 11.40.72
- 44.0 Prior to 11.44.20
- 46.0 Prior to 11.46.20
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/commvault-security-advisory-av26-899