EXPOSURES › CVE-2025-3928
CVE-2025-3928
HIGH ⌖ ON CISA KEV · EXPLOITEDA vulnerability in Commvault's Web Server allows authenticated attackers to execute webshells remotely, actively exploited in the wild.
Commvault's Web Server contains an unspecified vulnerability enabling remote, authenticated webshell creation and execution, currently under active exploitation. This poses a significant risk to DIB organizations using Commvault, potentially leading to data compromise and compliance failures (e.g., NIST 800-171 controls related to access control and incident response). Immediately verify patch status and review access controls.
Shame score — The active exploitation of a webshell vulnerability, allowing remote code execution, demonstrates a serious lapse in security controls and a potential for significant damage.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells.