CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Commvault security advisory (AV26-799)

unknown
Serial Number: AV26-799 Date: August 11, 2026 As of August 11, 2026, Commvault is affected by vulnerabilities in the following product: Commvault Cloud 11.36.0 Prior to 11.36.114 11.40.0 Prior to 11.40.63 11.44.0 Prior to 11.44.11 11.46.0 Prior to 11.46.10 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CV_2026_07_8 CV_2026_07_9 CV_2026_07_5 Commvault Cloud Security Advisories

CSIRTS triage

vendor: Commvaultproduct: Commvault CloudOtheraffected: 11.36.0 prior to 11.36.114, 11.40.0 prior to 11.40.63, 11.44.0 prior to 11.44.11, 11.46.0 prior to 11.46.10
What
Multiple vulnerabilities exist in Commvault Cloud across several versions.
Who is affected
Commvault Cloud deployments running versions 11.36.0, 11.40.0, 11.44.0, and 11.46.0 before the specified patch levels.
Urgency
Moderate to high urgency pending confirmation of severity details for CVE_2026_07_8, CVE_2026_07_9, and CVE_2026_07_5.
Action
Apply cumulative patches to update to 11.36.114, 11.40.63, 11.44.11, or 11.46.10 respectively.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Commvault Cloud

Get an email when a new Commvault Cloud advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-11
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/commvault-security-advisory-av26-799

More from Canadian Centre for Cyber Security