- Nation-State Hackers abusing a Commvault Zero-Day to target SaaS companies
- CISA warns users to patch their systems
- A large -scale campaign is currently underway it was said
The US Cyber Security and Infrastructure Security Agency (CISA) warns the recent violation of the Commvault could put many software-as-a-service (SaaS) providers at risk.
In a recently published security counseling, the agency said the attack is being monitored and called on Commvault’s customers to mitigate possible risks.
Commvault’s flagship product, Metallic. is a cloud-based SaaS data protection platform that provides secure backup and recovery to Microsoft 365, Endpoints, VMS, Databases and other workloads. It’s all hosted at Microsoft Azure, and CISA says named threat actors “can have access to client secrets for Commvault’s (Metallic) Microsoft 365 Backup SaaS solution.”
“This gave the threat actors unauthorized access to Commwault Customers’ M365 environments that have application secrets stored by Commvault.”
At the same time, Commvault published a blog post saying that Microsoft was reaching out to warn of a running state -sponsored cyberattack.
The company confirmed that a “handful of customers” was targeted through a zero-day vulnerability traced as CVE-2025-3928, an unspecified error in the Commvault Web server that can be exploited by a distant, approved striker.
Cisa added to its catalog of well-known utilized vulnerabilities (KEV) on April 28, giving the Federal Civil Executive Branch (FCCEB) Agencies a three-week deadline to patch things up. The error was set in versions 11.36.46, 11.32.89, 11.28.141 and 11.20.217 for Windows and Linux platforms.
“CISA believes that threat activity can be part of a larger campaign aimed at various SaaS companies’ sky applications with standard configurations and increased permits,” the agency added to the counseling.
The agency has also made a list of mitigation that companies must follow to minimize the chances of being hit. These include monitoring entra -audit logs, review of Microsoft logs, review of the list of application registrations and service principles in Entra and more. The entire list can be found on This link.
Via Registered