Skip to content
COOEY

EXPOSURES › CVE-2025-3928

CVE-2025-3928

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-04-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-3928 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedrce

A vulnerability in Commvault's Web Server allows authenticated attackers to execute webshells remotely, actively exploited in the wild.

Commvault's Web Server contains an unspecified vulnerability enabling remote, authenticated webshell creation and execution, currently under active exploitation. This poses a significant risk to DIB organizations using Commvault, potentially leading to data compromise and compliance failures (e.g., NIST 800-171 controls related to access control and incident response). Immediately verify patch status and review access controls.

Shame score — The active exploitation of a webshell vulnerability, allowing remote code execution, demonstrates a serious lapse in security controls and a potential for significant damage.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.