Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Commvault said a threat actor exploited CVE-2025-3928 as a zero-day during unauthorized activity in the company’s Azure environment. Microsoft notified Commvault on February 20, 2025, and Commvault disclosed its investigation’s findings on March 7. The flaw affects Commvault Web Server and requires valid Commvault credentials; it is not an unauthenticated vulnerability. Commvault says it patched its SaaS platform automatically, while self-managed customers should install the fixed maintenance release for their version.

What happened, and when?

According to Commvault’s March 7, 2025 statement, Microsoft notified the company on February 20 about unauthorized activity in Commvault’s Azure environment. Commvault attributed the activity to a suspected nation-state threat actor. The company said its forensic investigation found the actor had exploited a zero-day vulnerability, rotated affected credentials, and continued hardening its defenses.

Commvault issued security advisory CV_2025_03_1 on February 24, 2025. The advisory was updated May 1 and identifies the vulnerability as CVE-2025-3928. On May 27, 2025, Singapore’s Cyber Security Agency (CSA) published a separate alert reporting active exploitation in Metallic SaaS. That later alert adds a potential Microsoft 365 concern, but it does not establish that every Commvault customer or Microsoft 365 tenant was affected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is CVE-2025-3928?

CVE-2025-3928 is a high-severity vulnerability in Commvault Web Server. Commvault’s security advisory says exploitation requires an attacker to have valid, authenticated user credentials in the Commvault software environment. The stated consequence is the ability to create and execute a webshell on webservers. It is therefore not exploitable through unauthenticated access alone.

Commvault’s March 7 statement describes the flaw as a zero-day exploited during the Azure incident. The term means the vulnerability was exploited before a patch was available; it does not mean that exploitation required no credentials.

Which Commvault versions are affected?

Commvault lists these affected Windows and Linux release ranges and fixed maintenance releases:

Affected release Fixed release
11.36.0–11.36.45 11.36.46 and higher
11.32.0–11.32.88 11.32.89 and higher
11.28.0–11.28.140 11.28.141 and higher
11.20.0–11.20.216 11.20.217 and higher

These ranges and remediation instructions come from Commvault’s advisory CV_2025_03_1. Install the resolved maintenance release on the CommServe, Web Servers, and Command Center. Commvault explicitly says client computers are not impacted.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should administrators do?

For self-managed Commvault software

  1. Identify the installed Commvault release and compare it with the affected ranges in the table above.
  2. If the installation is in an affected range, install the corresponding fixed maintenance release on the CommServe, Web Servers, and Command Center, following the vendor advisory.
  3. Review access logs for unauthorized activity, check relevant indicators of compromise, and rotate Commvault credentials or client secrets where applicable. These are response precautions recommended by Singapore’s CSA; they are not evidence that a particular organization was compromised.

For Commvault SaaS and Metallic customers

Commvault says necessary SaaS patches, including this fix, were deployed automatically, so customers do not need to install the patch themselves. Automatic patching addresses the software fix; it does not establish that every account, stored secret, or connected Microsoft 365 tenant was unaffected. Singapore’s CSA advises relevant users to review access logs, rotate credentials and client secrets where applicable, and monitor for indicators of compromise.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about customer and Microsoft 365 impact?

Commvault said its investigation validated unauthorized access affecting “a handful of customers,” who were contacted for assistance. It did not publish an exact count or a detailed forensic list of data accessed. The company also said it found no unauthorized access to customer data it protects and reported no impact on its business operations or ability to deliver products and services. These are Commvault’s stated findings.

Singapore’s CSA later reported that exploitation was reportedly active in Metallic SaaS, which is used for Microsoft 365 backups. The agency said successful exploitation could let an authenticated remote attacker access customer Microsoft 365 environments where application secrets were stored by Commvault, as well as create and execute webshells. This describes a possible impact under the conditions in the alert—not proof that all Metallic customers, all stored secrets, or all backed-up Microsoft 365 data were accessed.

The CSA recommends affected product users update, review access logs, rotate credentials and client secrets where applicable, and monitor advisory indicators of compromise. Commvault separately said it rotated affected credentials. Neither recommendation nor reported action, by itself, establishes that an individual customer experienced compromise.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.