Commvault A.I CyberSecurity Scoring
Commvault
Company Information
Website:https://www.commvault.com
Employees number:3,481
Number of followers:185,345
NAICS:
Industry Type:Data Security Software Products
Homepage:commvault.com
Commvault Risk Score (AI oriented)
Between 750 and 799
CommvaultData Security Software Products
Updated:
28/03/2026
28/03/2026
763/1000
Fair
Baa
Commvault Global Score (TPRM)
xxxx
CommvaultData Security Software Products
Score locked

CommvaultFair
Current Score
763Baa (FAIR)
01000
3 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
754
MAY 2026
766
APRIL 2026
765
MARCH 2026
763
FEBRUARY 2026
763
JANUARY 2026
763
DECEMBER 2025
768
Cyber Attack
26 Dec 2025 • Commvault
Oracle Cloud, Azure and AWS: TeamPCP Turns Cloud Infrastructure into Crime Bots
TeamPCP Exploits Cloud Misconfigurations in Large-Scale Cybercrime Operation
750
CRITICAL-18
AMAORAMIC1770695748
TeamPCP Exploits Cloud Misconfigurations in Large-Scale Cybercrime Operation
A threat actor known as TeamPCP (also operating under aliases like PCPcat and ShellForce) is conducting automated, worm-like attacks on misconfigured and exposed cloud management services, compromising at least 60,000 servers worldwide since late December. The group’s campaign primarily targets Azure (60% of attacks), AWS (37%), and Google and Oracle cloud environments, exploiting well-documented vulnerabilities and misconfigurations rather than developing new attack methods.
TeamPCP’s operations involve scanning for exposed Docker APIs, Kubernetes clusters, Ray dashboards, and systems with leaked secrets (such as `.env` files). Once inside, the group deploys malicious Python and Shell scripts to install proxies, tunneling software, and persistence mechanisms, effectively converting compromised infrastructure into a self-propagating botnet. A key tool in their arsenal is the React2Shell vulnerability (CVE-2025-29927), which allows remote command execution and data exfiltration.
The group monetizes its attacks through multiple revenue streams, including:
- Cryptocurrency mining using hijacked compute resources.
- Data theft and extortion, with stolen records including personal IDs, employment records, and résumés published on a leak site operated by an affiliate, ShellForce.
- Selling access to compromised systems for use as proxies or command-and-control infrastructure.
- Ransomware deployment, leveraging infected systems as launchpads for further attacks.
Notably, TeamPCP has targeted JobsGO, a Vietnamese recruitment platform, exfiltrating over two million records containing sensitive personal and professional data. Most victims are located in South Korea, Canada, the U.S., Serbia, and the UAE, with stolen information often used for phishing, impersonation, or account takeovers.
Despite its sophistication, TeamPCP’s techniques are not novel the group relies on automated exploitation of known vulnerabilities and recycled tooling. Security firm Flare warns that the threat actor’s strength lies in its large-scale automation, turning exposed cloud infrastructure into a distributed criminal ecosystem. The group also maintains a Telegram channel (launched in November, with ~700 members) for updates and reputation-building, though researchers suggest it may have operated under previous aliases.
The campaign underscores the risks of unsecured cloud control planes, leaked credentials, and poor access controls, as TeamPCP continues to industrialize existing attack vectors with alarming efficiency.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
768
OCTOBER 2025
768
SEPTEMBER 2025
767
AUGUST 2025
767
JULY 2025
767
APRIL 2025
770
Vulnerability
01 Apr 2025 • Commvault
Commvault
Commvault Command Center Path Traversal Vulnerability
766
LOW-4
COM743042525
In April 2025, researchers uncovered a critical path traversal vulnerability (CVE-2025-34028) in Commvault Command Center Innovation Release (versions 11.38.0 to 11.38.19). This flaw allows unauthenticated attackers to trigger a server-side request forgery that fetches and unpacks a malicious ZIP archive from a remote host. Once extracted, the payload installs a reverse shell, granting full remote code execution privileges on the backup management server. Successful exploitation can lead to unauthorized access to backup data, tampering or deletion of critical recovery sets, or the deployment of additional malware across protected endpoints. Organizations relying on these on-premise systems risk severe operational disruption due to compromised backup integrity and potential data loss. Threat actors could exfiltrate sensitive corporate and customer information stored in backups, undermine disaster recovery processes, and stage lateral movements to other internal assets. Unpatched instances may also serve as a foothold for persistent intrusion, ultimately eroding trust in data protection mechanisms, causing financial and reputational damage, and delaying incident response during recovery efforts. Though a patch is available in versions 11.38.20 and later, failure to update exposes enterprises to significant security and compliance risks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2025
774
Vulnerability
01 Mar 2025 • Commvault
Commvault
Commvault Webserver Vulnerability (CV_2025_03_1)
770
CRITICAL-4
COM949031025
Commvault faced a critical Webserver vulnerability (CV_2025_03_1) affecting versions 11.20 through 11.36, posing substantial risks to data protection and system integrity. If exploited, this vulnerability could have allowed attackers to execute webshells, gaining unauthorized system control. Commvault quickly released patches for Linux and Windows platforms, mitigating the risk. Organizations using affected versions were urged to update immediately to prevent potential data breaches, unauthorized access, and operational disruptions, highlighting the importance of maintaining strict cybersecurity practices and regular software updates.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Commvault ??
What was Commvault's A.I Rankiteo Cyber Score in May 2026 ??
What was Commvault's A.I Rankiteo Cyber Score in April 2026 ??
What was Commvault's A.I Rankiteo Cyber Score in March 2026 ??
What was Commvault's A.I Rankiteo Cyber Score in February 2026 ??
What was Commvault's A.I Rankiteo Cyber Score in January 2026 ??
What was Commvault's A.I Rankiteo Cyber Score in December 2025 ??
What was Commvault's A.I Rankiteo Cyber Score in November 2025 ??
What was Commvault's A.I Rankiteo Cyber Score in October 2025 ??
What was Commvault's A.I Rankiteo Cyber Score in September 2025 ??
What was Commvault's A.I Rankiteo Cyber Score in August 2025 ??
What was Commvault's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Commvault's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Commvault ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Commvault's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?