CVE-2025-3928
Last modified
CVE-2025-3928 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. CISA has confirmed active exploitation in the wild. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Commvault | Commvault | >= 11.20.0, < 11.20.217 |
| Commvault | Commvault | >= 11.28.0, < 11.28.141 |
| Commvault | Commvault | >= 11.32.0, < 11.32.89 |
| Commvault | Commvault | >= 11.36.0, < 11.36.46 |
References
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-3928Third Party Advisory, US Government Resource
- https://www.cisa.gov/news-events/alerts/2025/05/22/advisory-update-cyber-threat-activity-targeting-commvaults-saas-cloud-application-metallicThird Party Advisory, US Government Resource
- https://www.commvault.com/blogs/customer-security-updateVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3928US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-3928?
How severe is CVE-2025-3928?
How do I fix CVE-2025-3928?
Are you affected by CVE-2025-3928?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
