Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Commvault/
  3. Commvault Microsoft 365 Backup

Commvault Microsoft 365 Backup

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 16 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Cloud-based backup and recovery solution for Microsoft 365 workloads

by Commvault · commvault.com · source ↗

Known CVEs (16)2 newAbout this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-13738 ↗new2026

    CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault in…

  • CVE-2026-13737 ↗new2026

    CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, includ…

  • CVE-2025-34136 ↗2025

    An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Inj…

  • CVE-2024-13976 ↗2025

    A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit…

  • CVE-2024-13975 ↗2025

    A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client syst…

  • CVE-2025-3928 ↗⚠ actively exploitedHIGH 8.82025

    Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors …

  • CVE-2025-34028 ↗⚠ actively exploitedCRITICAL 10.02025

    The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path tra…

  • CVE-2021-34997 ↗HIGH 8.82022

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the ex…

  • CVE-2021-34996 ↗HIGH 8.82022

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the ex…

  • CVE-2021-34995 ↗HIGH 8.82022

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the ex…

  • CVE-2021-34994 ↗HIGH 8.82022

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the ex…

  • CVE-2021-34993 ↗CRITICAL 9.82022

    This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2020-25780 ↗HIGH 7.52020

    In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur such that an attempt to view a log file can instead…

  • CVE-2017-18044 ↗CRITICAL 9.82018

    A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside the Commvault service does not properly validate the…

  • CVE-2017-3195 ↗CRITICAL 9.82017

    Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution…

  • CVE-2015-7253 ↗HIGH 10.02015

    The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a cookie.

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Backup as a Service products

see all →
  • Acsense IAM Resilience Platform · Acsense
  • Ahsay Backup Amazon S3 · Ahsay Systems Corporation
  • Ahsay Backup Microsoft Azure · Ahsay Systems Corporation
  • Ahsay Google Workspace Backup · Ahsay Systems Corporation
  • Arcserve Cloud Cyber Resilient Storage · Arcserve
  • Arcserve Cyber Resilient Storage · Arcserve
  • Arpio · Arpio
  • AvePoint Products · AvePoint