Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Commvault

Commvault Vendor Cyber Rating & Cyber Score

commvault.com

Commvault (NASDAQ: CVLT) is the gold standard in cyber resilience, helping more than 100,000 organizations to uncover, take action, and rapidly recover from cyber attacks—keeping data safe and businesses resilient and moving forward. Today, Commvault offers the only cyber resilience platform that combines the best data security and rapid recovery at enterprise scale across any workload, anywhere with advanced AI-driven automation—at the lowest TCO.


Commvault A.I CyberSecurity Scoring

Commvault
Company Information
Website:https://www.commvault.com
Employees number:3,481
Number of followers:185,345
NAICS:
Industry Type:Data Security Software Products
Homepage:commvault.com
Commvault Risk Score (AI oriented)
Between 750 and 799
logo
CommvaultData Security Software Products
Updated:
28/03/2026
763/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Commvault Global Score (TPRM)
xxxx
logo
CommvaultData Security Software Products
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Commvault
CommvaultFair
Current Score
763Baa (FAIR)
01000
3 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
754Before Incident
MAY 2026
766Before Incident
APRIL 2026
765Before Incident
MARCH 2026
763Before Incident
FEBRUARY 2026
763Before Incident
JANUARY 2026
763Before Incident
DECEMBER 2025
768Before Incident
Cyber Attack
26 Dec 2025Commvault
Oracle Cloud, Azure and AWS: TeamPCP Turns Cloud Infrastructure into Crime Bots

TeamPCP Exploits Cloud Misconfigurations in Large-Scale Cybercrime Operation

750After Incident
CRITICAL-18
AMAORAMIC1770695748
TeamPCP Exploits Cloud Misconfigurations in Large-Scale Cybercrime Operation A threat actor known as TeamPCP (also operating under aliases like PCPcat and ShellForce) is conducting automated, worm-like attacks on misconfigured and exposed cloud management services, compromising at least 60,000 servers worldwide since late December. The group’s campaign primarily targets Azure (60% of attacks), AWS (37%), and Google and Oracle cloud environments, exploiting well-documented vulnerabilities and misconfigurations rather than developing new attack methods. TeamPCP’s operations involve scanning for exposed Docker APIs, Kubernetes clusters, Ray dashboards, and systems with leaked secrets (such as `.env` files). Once inside, the group deploys malicious Python and Shell scripts to install proxies, tunneling software, and persistence mechanisms, effectively converting compromised infrastructure into a self-propagating botnet. A key tool in their arsenal is the React2Shell vulnerability (CVE-2025-29927), which allows remote command execution and data exfiltration. The group monetizes its attacks through multiple revenue streams, including: - Cryptocurrency mining using hijacked compute resources. - Data theft and extortion, with stolen records including personal IDs, employment records, and résumés published on a leak site operated by an affiliate, ShellForce. - Selling access to compromised systems for use as proxies or command-and-control infrastructure. - Ransomware deployment, leveraging infected systems as launchpads for further attacks. Notably, TeamPCP has targeted JobsGO, a Vietnamese recruitment platform, exfiltrating over two million records containing sensitive personal and professional data. Most victims are located in South Korea, Canada, the U.S., Serbia, and the UAE, with stolen information often used for phishing, impersonation, or account takeovers. Despite its sophistication, TeamPCP’s techniques are not novel the group relies on automated exploitation of known vulnerabilities and recycled tooling. Security firm Flare warns that the threat actor’s strength lies in its large-scale automation, turning exposed cloud infrastructure into a distributed criminal ecosystem. The group also maintains a Telegram channel (launched in November, with ~700 members) for updates and reputation-building, though researchers suggest it may have operated under previous aliases. The campaign underscores the risks of unsecured cloud control planes, leaked credentials, and poor access controls, as TeamPCP continues to industrialize existing attack vectors with alarming efficiency.
INCIDENT DETAILS -
TYPE
Cloud Misconfiguration ExploitationBotnetData TheftRansomware
MOTIVATION
Financial gainData extortionCryptocurrency miningSelling access to compromised systems
IMPACT
Data Compromised: Over two million records (personal IDs, employment records, résumés)Systems Affected: 60,000+ servers worldwideOperational Impact: Compromised infrastructure converted into a botnet for further attacksIdentity Theft Risk: High (personal and professional data used for phishing, impersonation, or account takeovers)
DATA BREACH
Personal IDsEmployment recordsRésumésNumber Of Records Exposed: Over two millionSensitivity Of Data: High (personally identifiable and professional information)
NOVEMBER 2025
768Before Incident
OCTOBER 2025
768Before Incident
SEPTEMBER 2025
767Before Incident
AUGUST 2025
767Before Incident
JULY 2025
767Before Incident
APRIL 2025
770Before Incident
Vulnerability
01 Apr 2025Commvault
Commvault

Commvault Command Center Path Traversal Vulnerability

766After Incident
LOW-4
COM743042525
In April 2025, researchers uncovered a critical path traversal vulnerability (CVE-2025-34028) in Commvault Command Center Innovation Release (versions 11.38.0 to 11.38.19). This flaw allows unauthenticated attackers to trigger a server-side request forgery that fetches and unpacks a malicious ZIP archive from a remote host. Once extracted, the payload installs a reverse shell, granting full remote code execution privileges on the backup management server. Successful exploitation can lead to unauthorized access to backup data, tampering or deletion of critical recovery sets, or the deployment of additional malware across protected endpoints. Organizations relying on these on-premise systems risk severe operational disruption due to compromised backup integrity and potential data loss. Threat actors could exfiltrate sensitive corporate and customer information stored in backups, undermine disaster recovery processes, and stage lateral movements to other internal assets. Unpatched instances may also serve as a foothold for persistent intrusion, ultimately eroding trust in data protection mechanisms, causing financial and reputational damage, and delaying incident response during recovery efforts. Though a patch is available in versions 11.38.20 and later, failure to update exposes enterprises to significant security and compliance risks.
INCIDENT DETAILS -
TYPE
Path Traversal Vulnerability
MOTIVATION
Unauthorized access to backup dataTampering or deletion of critical recovery setsDeployment of additional malwareExfiltration of sensitive informationUndermining disaster recovery processesLateral movements to other internal assets
IMPACT
backup datasensitive corporate and customer informationbackup management serverOperational Impact: Severe operational disruptionBrand Reputation Impact: Erosion of trust in data protection mechanisms
DATA BREACH
backup datasensitive corporate and customer information
MARCH 2025
774Before Incident
Vulnerability
01 Mar 2025Commvault
Commvault

Commvault Webserver Vulnerability (CV_2025_03_1)

770After Incident
CRITICAL-4
COM949031025
Commvault faced a critical Webserver vulnerability (CV_2025_03_1) affecting versions 11.20 through 11.36, posing substantial risks to data protection and system integrity. If exploited, this vulnerability could have allowed attackers to execute webshells, gaining unauthorized system control. Commvault quickly released patches for Linux and Windows platforms, mitigating the risk. Organizations using affected versions were urged to update immediately to prevent potential data breaches, unauthorized access, and operational disruptions, highlighting the importance of maintaining strict cybersecurity practices and regular software updates.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
MOTIVATION
Unauthorized System Control
IMPACT
WebserverPotential Data BreachesUnauthorized AccessOperational Disruptions

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Commvault ?
?
What was Commvault's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Commvault's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Commvault's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Commvault's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Commvault's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Commvault's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Commvault's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Commvault's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Commvault's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Commvault's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Commvault's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Commvault's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Commvault ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Commvault's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?