Commvault Systems Inc. maintains a focused portfolio of backup, recovery, and data-management platforms that occupy a critical position in enterprise infrastructure, where their control over system restoration and file access creates a high-value attack surface. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, an elevated tendency toward confirmed in-the-wild exploitation, and a high tendency to acquire public exploit code. The recurring exposure centers on the flagship CommCell and Edge products and clusters around pathname traversal, OS command injection, unrestricted file upload, and exposed dangerous methods—weakness classes that directly enable adversaries to read, write, or execute commands within backup repositories and management tiers. Defenders should treat this vendor's advisories as high-priority across their data-protection deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Commvault Systems Inc. over time
Of all the CVEs published by Commvault Systems Inc. as a CNA, 100.0% affect products that Commvault Systems Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Commvault Systems Inc., 27.8% are self-published by Commvault Systems Inc. as a CNA.
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-34028CRITICAL The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vu | Apr 22, 2025 | 10.0 | 98 | YES | YES |
CVE-2017-18044CRITICAL A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside the Commvault service does not p | Jan 19, 2018 | 9.8 | 77 | NO | YES |
CVE-2021-34996HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this v | Jan 13, 2022 | 8.8 | 73 | NO | NO |
CVE-2025-3928HIGH Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised | Apr 25, 2025 | 8.8 | 66 | YES | NO |
CVE-2021-34995HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this v | Jan 13, 2022 | 8.8 | 66 | NO | NO |
CVE-2025-57790HIGH A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to r | Aug 20, 2025 | 8.8 | 55 | NO | YES |
CVE-2017-3195CRITICAL Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbi | Dec 16, 2017 | 9.8 | 53 | NO | YES |
CVE-2025-57791MEDIUM A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input val | Aug 20, 2025 | 6.5 | 51 | NO | YES |
CVE-2025-57788MEDIUM A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not elim | Aug 20, 2025 | 6.5 | 49 | NO | YES |
CVE-2020-25780HIGH In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur such that an attempt to view a | Oct 29, 2020 | 7.5 | 37 | NO | YES |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Commvault Systems Inc..
Media articles that mention a CVE ID that affects a product developed by Commvault Systems Inc. — matched by CVE ID, not by vendor name.