CVE-2025-3928
Last modified
CVE-2025-3928 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. CISA has confirmed active exploitation in the wild. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Commvault | Commvault | >= 11.20.0, < 11.20.217 |
| Commvault | Commvault | >= 11.28.0, < 11.28.141 |
| Commvault | Commvault | >= 11.32.0, < 11.32.89 |
| Commvault | Commvault | >= 11.36.0, < 11.36.46 |
References
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-3928Third Party Advisory, US Government Resource
- https://www.cisa.gov/news-events/alerts/2025/05/22/advisory-update-cyber-threat-activity-targeting-commvaults-saas-cloud-application-metallicThird Party Advisory, US Government Resource
- https://www.commvault.com/blogs/customer-security-updateVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3928US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-3928?
How severe is CVE-2025-3928?
How do I fix CVE-2025-3928?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-39240Some Hikvision Wireless Access Point are vulnerable to authe…7.2
- CVE-2025-39245There is a CSV Injection Vulnerability in some HikCentral Ma…4.7
- CVE-2025-39246There is an Unquoted Service Path Vulnerability in some HikC…5.3
- CVE-2025-39247There is an Access Control Vulnerability in some HikCentral …8.6
- CVE-2025-3925BrightSign players running BrightSign OS series 4 prior to v…8.5
- CVE-2025-3927Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not…9.8
- CVE-2025-3929An XSS issue was discovered in MDaemon Email Server version …6.1
- CVE-2025-3930Strapi uses JSON Web Tokens (JWT) for authentication. After …6.3
- CVE-2025-3931A flaw was found in Yggdrasil, which acts as a system broker…7.8
- CVE-2025-3932It was possible to craft an email that showed a tracking lin…6.5
- CVE-2025-3933A Regular Expression Denial of Service (ReDoS) vulnerability…5.3
- CVE-2025-39348Deserialization of Untrusted Data vulnerability in ThemeGood…9.8
Are you affected by CVE-2025-3928?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
