COMMVAULT disclosed three critical vulnerabilities (CVE-2026-13737, CVE-2026-13738, CVE-2026-13739) affecting its data protection software, enabling remote attackers to bypass authorization checks and forge server requests. These vulnerabilities have a high CVSS score of up to 9.2. No confirmed exploitation has been reported, and patches are available. Affected versions include 11.36, 11.40, 11.44, and 11.46. Immediate updates to specific newer versions (11.46.10, 11.44.11, 11.40.63, 11.36.114) are necessary to secure systems.
Commvault fixes critical bugs allowing remote server takeover
CyberSIXT Evidence Panel
Article by CyberSIXT