Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Commvault Systems Inc.

First CVE: Nov 4, 2015Active for: 11 yearsTotal CVEs: 18
83.7
VTI Score
TOP TARGET

Commvault Systems Inc. maintains a focused portfolio of backup, recovery, and data-management platforms that occupy a critical position in enterprise infrastructure, where their control over system restoration and file access creates a high-value attack surface. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, an elevated tendency toward confirmed in-the-wild exploitation, and a high tendency to acquire public exploit code. The recurring exposure centers on the flagship CommCell and Edge products and clusters around pathname traversal, OS command injection, unrestricted file upload, and exposed dangerous methods—weakness classes that directly enable adversaries to read, write, or execute commands within backup repositories and management tiers. Defenders should treat this vendor's advisories as high-priority across their data-protection deployments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
11.1%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Commvault Systems Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2015
10 years ago
Most Recent CVE
Jan 7, 2026
198 days ago

Self-Reporting Analysis

Of all the CVEs published by Commvault Systems Inc. as a CNA, 100.0% affect products that Commvault Systems Inc. develops as a vendor.

100.0%
Self-reported: 5 (100.0%)
Third-party: 0 (0.0%)

Of all the CVEs published that affect products developed by Commvault Systems Inc., 27.8% are self-published by Commvault Systems Inc. as a CNA.

27.8%
72.2%
Self-published: 5 (27.8%)
Other CNAs: 13 (72.2%)

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-34028CRITICAL
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vu
Apr 22, 202510.098YESYES
CVE-2017-18044CRITICAL
A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside the Commvault service does not p
Jan 19, 20189.877NOYES
CVE-2021-34996HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this v
Jan 13, 20228.873NONO
CVE-2025-3928HIGH
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised
Apr 25, 20258.866YESNO
CVE-2021-34995HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this v
Jan 13, 20228.866NONO
CVE-2025-57790HIGH
A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to r
Aug 20, 20258.855NOYES
CVE-2017-3195CRITICAL
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbi
Dec 16, 20179.853NOYES
CVE-2025-57791MEDIUM
A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input val
Aug 20, 20256.551NOYES
CVE-2025-57788MEDIUM
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not elim
Aug 20, 20256.549NOYES
CVE-2020-25780HIGH
In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur such that an attempt to view a
Oct 29, 20207.537NOYES
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
28%
50%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.6%)
Network16 (88.9%)
Unknown1 (5.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (94.4%)
High0 (0.0%)
Unknown1 (5.6%)
User Interaction
None16 (88.9%)
Unknown1 (5.6%)
Required1 (5.6%)
Privileges Required
Low9 (50.0%)
High0 (0.0%)
None8 (44.4%)
Unknown1 (5.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
2 CVEs
11.1% of CVEs· 100th percentile
Metasploit
4 CVEs
22.2% of CVEs· 99th percentile
Nuclei
4 CVEs
22.2% of CVEs· 97th percentile
ExploitDB
1 CVE
5.6% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Commvault Systems Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Commvault Systems Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Commvault Systems Inc.'s Products

View all 6 CNAs →

Top CWEs