Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation Confirmed

The Hacker News by The Hacker News
May 5, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


May 05, 2025Ravie LakshmananVulnerability / Zero-Day

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity security flaw impacting Commvault Command Center to its Known Exploited Vulnerabilities (KEV) catalog, a little over a week after it was publicly disclosed.

The vulnerability in question is CVE-2025-34028 (CVSS score: 10.0), a path traversal bug that affects 11.38 Innovation Release, from versions 11.38.0 through 11.38.19. It has been addressed in versions 11.38.20 and 11.38.25.

“Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code,” CISA said.

Cybersecurity

The flaw essentially permits an attacker to upload ZIP files that, when decompressed on the target server, could result in remote code execution.

Cybersecurity company watchTowr Labs, which was credited with discovering and reporting the bug, said the problem resides in an endpoint called “deployWebpackage.do” that triggers a pre-authenticated Server-Side Request Forgery (SSRF), ultimately resulting in code execution when using a ZIP archive file containing a malicious .JSP file.

It’s currently not known in what context the vulnerability is being exploited, but the development makes it the second Commvault flaw to be weaponized in real-world attacks after CVE-2025-3928 (CVSS score: 8.7), an unspecified issue in the Commvault Web Server that allows a remote, authenticated attacker to create and execute web shells.

The company revealed last week that the exploitation activity affected a small number of customers but noted that there has been no unauthorized access to customer backup data.

In light of active exploitation of CVE-2025-34028, Federal Civilian Executive Branch (FCEB) agencies are required to apply the necessary patches by May 23, 2025, to secure their networks.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
YäRKEN Raises Funds from 1982 Ventures to Expand AI-Driven IT Financial Management Across North American Enterprise Clients

YäRKEN Raises Funds from 1982 Ventures to Expand AI-Driven IT Financial Management Across North American Enterprise Clients

Recommended.

Stocks making the biggest moves premarket: Generac, Lennar, Nike & more

September 17, 2026
Startup Across AI Looks To Improve Agentic AI Tech For Business Workflows

Startup Across AI Looks To Improve Agentic AI Tech For Business Workflows

December 24, 2024

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

These Russian Mathematicians Taught AI Models How to Talk to Each Other Without Using Words

September 2, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio