securityonline.info 8/19/2026, 2:02:33 PM · external

Commvault fixes critical bugs allowing remote server takeover

Commvault fixes critical bugs allowing remote server takeover
CyberSIXT Evidence Panel

COMMVAULT disclosed three critical vulnerabilities (CVE-2026-13737, CVE-2026-13738, CVE-2026-13739) affecting its data protection software, enabling remote attackers to bypass authorization checks and forge server requests. These vulnerabilities have a high CVSS score of up to 9.2. No confirmed exploitation has been reported, and patches are available. Affected versions include 11.36, 11.40, 11.44, and 11.46. Immediate updates to specific newer versions (11.46.10, 11.44.11, 11.40.63, 11.36.114) are necessary to secure systems.

View Primary Source Via securityonline.info

Article by CyberSIXT