• News/
  • https://www.theregister.com/2025/05/23/cisa_commvault_zero_day/

CISA says SaaS providers in firing line after Commvault zero-day Azure attack

The Register
·
Connor Jones
·
Published May 23, 2025
·
Updated

The Cybersecurity and Infrastructure Security Agency (CISA) is warning that SaaS companies are under fire from criminals on the prowl for cloud apps with weak security. Apps with default configurations and elevated permissions are the aim of these attacks, although the US agency did not attribute the activity to a specific group in a message issued this week. However, the warning follows an advisory published by data security biz Commvault earlier this month, which revealed unauthorized activity was detected in its Azure environments. Danielle Sheer, chief trust officer at Commvault, said in a blog post that Microsoft contacted the company in February, reporting signs that nation-state baddies had broken into Commvault's systems. A separate advisory at the time confirmed that "a handful of customers" were affected after the suspected nation-state attackers exploited a Commvault zero-day (CVE-2025-3928 – 8.7). That vulnerability remains unspecified, but it requires authenticated credentials in order to make use of it. It was added to CISA's Known Exploited Vulnerability (KEV) catalog on April 28 with the added detail that successful exploitation can lead to remote attackers creating and executing web shells. Each KEV entry also lists whether the vulnerability is known to be used in ransomware attacks. In this case, the value for CVE-2025-3928 is "unknown." Sheer confirmed there was no access to the data Commvault protects for its customers and the event had no impact on Commva...

Read full article

Affected Software

2 affected components
Commvault Azure-hosted M365 backup SaaS solution
Commvault Commvault=8.7
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a warning from CISA about a zero-day vulnerability affecting Commvault's Azure-hosted M365 backup SaaS solution.

2

What security implications are discussed in the article?

The article highlights that criminals are targeting SaaS providers with weak security and default configurations, posing a significant threat to cloud applications.

3

What products or software are affected by the zero-day vulnerability?

The affected software includes Commvault's Azure-hosted M365 backup SaaS solution and Commvault version 8.7.

4

Who issued the warning regarding the zero-day attack?

The warning regarding the zero-day attack was issued by the Cybersecurity and Infrastructure Security Agency (CISA).

5

What type of companies are specifically mentioned as being at risk in the article?

The article specifically mentions SaaS companies as being at risk from cybercriminals exploiting vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203