These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-77106 is a HIGH severity vulnerability affecting Cvlaunchd in Commvault Cloud. The vulnerability stems from a missing authorization issue impacting command execution authorization. Defenders responsible for Commvault Cloud installations, including Commserve, Webserver, Command Center, Media Agents, Clients, and HyperScale X, should assess exposure and prioritize upgrading to resolved maintenance [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-08T13:17:25.730Z and has not been modified since then. The Private Metrics Server contained an SQL injection condition affecting database operations. This issue impacts Commvault Cloud deployments using Private Metrics Server, potentially disrupting database operations and affecting data integrity a [truncated]
A high-severity vulnerability was found in Commvault Cloud's Private Metrics Server, allowing unauthorized metrics upload and service disruption. The issue, tracked as CVE-2026-77097, has a CVSS score of 8.8 and requires immediate attention from Commvault Cloud administrators. This vulnerability affects the metrics upload functionality and service availability of Commvault Cloud's Private Metrics Server. [truncated]
CVE-2026-77092 is a HIGH severity vulnerability affecting Commvault Cloud's Content Extractor due to deserialization of untrusted data, impacting privilege management. The vulnerability affects specific versions, including 11.36.0 to 11.36.123, 11.40.0 to 11.40.72, 11.44.0 to 11.44.20, and 11.46.0 to 11.46.20. Software customers are advised to upgrade to a resolved maintenance release. Defenders should as [truncated]
CVE-2026-77091 is a high-severity path traversal vulnerability in Commvault Cloud, affecting security feature enforcement with a CVSS score of 8.5. Defenders should assess exposure and prioritize upgrading to a resolved maintenance release and updating Content Extractor and Index Store. The vulnerability allows attackers to bypass security controls, potentially leading to unauthorized access and data brea [truncated]
CVE-2026-77089 is a critical authentication bypass issue affecting privilege management in Commvault Cloud's Command Center API. The issue has a CVSS score of 9.3 and is considered critical. Commvault customers are advised to upgrade to a resolved maintenance release. This vulnerability allows for unauthorized access to the Command Center API, potentially leading to privilege management issues. It require [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:37.180Z and has not been modified since then. The CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, [truncated]
CVE-2025-34028 is a path traversal vulnerability affecting Commvault Command Center that CISA added to the Known Exploited Vulnerabilities catalog on 2025-05-02. Because it is listed in KEV, organizations should treat it as an active-risk issue and prioritize remediation using the vendor’s guidance or CISA’s recommended actions.
CVE-2025-3928 is an unspecified Commvault Web Server vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-04-28. Because it is KEV-listed, defenders should treat it as an active-risk issue even though the supplied public record does not include a technical exploit description or CVSS score. The official guidance points administrators to apply vendor mitigations, follow appl [truncated]