CISA has issued a new security warning about a critical vulnerability affecting the Commvault Web Server, built into one of the industry’s leading data protection platforms. This alert comes as security teams worldwide scramble to assess exposure and mitigate risk, following the vulnerability’s addition to CISA’s Known Exploited Vulnerabilities (KEV) Catalog on April 28, 2025. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. However, researchers clarify that the flaw enables attackers with valid credentials to gain remote code execution (RCE) capabilities, specifically by uploading and running webshells-malicious scripts that grant attackers control over targeted systems. Security analysts warn that, even though exploitation currently requires authentication, many organizations fail to enforce strong access controls, leaving them vulnerable. Kaaviya is a Security Editor and fellow reporter with Cyber Security News. While there is no current public confirmation that CVE-2025-3928 has been leveraged in major ransomware campaigns, its ability to enable webshell deployment raises significant alarms. Webshells are a favorite tool among threat actors for establishing persistence, data exfiltration, lateral movement, and launching follow-on attacks, including ransomware. Assigned CVE-2025-3928, the flaw allows remote, authenticated attackers to create and execute webshells on compromised servers. According to CISA and initial advisories, the vulnerability is “unspecified,” meaning details have not been publicly disclosed, which is likely to prevent further exploitation. She is covering various cyber security incidents happening in the Cyber Space. Commvault, known for its enterprise-grade backup and recovery solutions, has quickly responded by releasing a patch and urging its customers to update immediately. With ransomware operators increasingly targeting backup solutions, even a single lapse can have devastating, organization-wide consequences. Users must consult Commvault’s official advisory and CISA’s guidance on the newly added CVE-2025-3928 for more information.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 29 Apr 2025 05:40:08 +0000