CVE-2025-3928
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2025-3928. We'll provide specific mitigation strategies based on your environment and risk profile.
CVSS Score
V3.1EPSS Score
v2025.03.14There is a 12.7% chance that this vulnerability will be exploited in the wild within the next 30 days.
Attack Vector Metrics
Impact Metrics
Description
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.
Available Exploits
Related News
Enterprise data backup platform Commvault has revealed that an unknown nation-state threat actor breached its Microsoft Azure environment by exploiting CVE-2025-3928 but emphasized there is no evidence of unauthorized data access. "This activity has affected …
The Cybersecurity and Infrastructure Security Agency (CISA) has added three new flaws to its Known Exploited Vulnerabilities catalog on Monday, affecting Commvault (CVE-2025-3928), Active! Mail (CVE-2025-42599), and Broadcom Brocade (CVE-2025-1976) solutions.…
Affected Products
Known Exploited Vulnerability
This vulnerability is actively being exploited in the wild
Remediation Status
Due Date
Added to KEV
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected Product
Ransomware Risk
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Advisory Details
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
Advisory provided by GitHub Security Advisory Database. Published: April 25, 2025, Modified: May 27, 2025
Social Media Intelligence
Real-time discussions and threat intelligence from social platforms
China's Silk Typhoon Breaches North American Cloud Networks **Date:** 23-Aug-25 China's state-sponsored hacking group Silk Typhoon has intensified cyberattacks on North American cloud networks, exploiting zero-day vulnerabilities in products like Commvault and Citrix Netscaler to access sensitive government and defense data. Since late spring 2025, the group has targeted software-as-a-service …
🚨 Threat Intel: MURKY PANDA (China-nexus adversary) 🚨 CrowdStrike reports **MURKY PANDA** has been actively targeting **government, tech, academia, legal, & professional services in North America** since at least 2023. Key TTPs: 🔹 Trusted-relationship compromises in the **cloud** 🔹 Rapid exploitation of **n-days & 0-days** (Citrix CVE-2023-3519, Commvault CVE-2025-3928) 🔹 …