Commvault Reveals Targeted Cyberattack by Nation-State Actor, Takes Swift Action to Secure Azure Environment
Commvault has confirmed a targeted cyber intrusion into its Microsoft Azure environment earlier this year, carried out by a sophisticated nation-state threat actor leveraging a previously unknown vulnerability. The breach, detected on February 20, 2025, was first flagged by Microsoft, triggering an immediate and coordinated incident response.
The vulnerability—now tracked as CVE-2025-3928—was embedded in Commvault’s Web Server software and exploited by attackers who had authenticated access with limited privileges. This allowed them to deploy webshells and attempt lateral movement. While the exploit affected a limited subset of systems, Commvault stressed that no customer backup data was compromised and core operations remained fully intact throughout the incident.
Danielle Sheer, Commvault’s Chief Trust Officer, emphasized the company’s rapid mobilization. “With support from top-tier cybersecurity firms and federal agencies, we moved quickly to isolate and neutralize the threat,” she said. “The trust our customers place in us is non-negotiable, and we’re committed to transparency and resilience.”
The now-patched flaw was serious enough to earn a CVSS score of 8.8 and inclusion in the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities Catalog. Federal agencies have until May 19, 2025, to remediate the issue on any affected Commvault systems.
Although the attackers required valid credentials to exploit the flaw, Commvault noted that this highlights the increasing trend of adversaries chaining low-privilege access with zero-day exploits to infiltrate hybrid cloud environments.
As part of its remediation and hardening strategy, Commvault:
- Released updated patches across supported versions
- Rotated credentials in impacted systems
- Partnered with CISA, the FBI, and independent security researchers
- Published an in-depth security advisory with protective actions for customers
Recommended customer actions include enforcing Conditional Access policies in Azure AD and Microsoft 365, routinely rotating and syncing client secrets, and monitoring for unusual sign-in patterns—particularly from a list of known malicious IP addresses identified in the attack.
Malicious IPs to block:
- 108.69.148.100
- 128.92.80.210
- 184.153.42.129
- 108.6.189.53
- 159.242.42.20
“We understand the landscape is evolving, and so are we,” Sheer added. “By sharing what we’ve learned, we’re not just protecting our own environment—we’re helping fortify the broader digital ecosystem.”
This incident underscores the heightened risks posed by state-sponsored threat actors and the critical need for constant vigilance and adaptive security architecture across SaaS, IaaS, and hybrid environments.




