DIRAS TAKE
Treat this as high urgency: the flaw scores 9.8 and no fixes are published for the affected 11.x releases, so immediately reduce exposure and prepare to apply vendor updates when released.
What is CVE-2026-77092?
An unauthenticated attacker can exploit a deserialization of untrusted data flaw in Commvault Cloud to impact privilege management and gain elevated control over the affected component. CVE-2026-77092 is a CWE-502 issue affecting Commvault Cloud releases in the 11.x line: 11.46.0–11.46.19, 11.44.0–11.44.19, 11.40.0–11.40.71 and 11.36.0–11.36.122. The vulnerability requires only the ability to reach the vulnerable service; no user interaction or credentials are listed in the available facts. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Commvault Commvault Cloud are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 11.x | 11.46.0 – 11.46.19 | |
| 11.x | 11.44.0 – 11.44.19 | |
| 11.x | 11.40.0 – 11.40.71 | |
| 11.x | 11.36.0 – 11.36.122 |
Is CVE-2026-77092 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-77092
- Restrict network access to Commvault Cloud management endpoints to trusted networks and VPNs.
- Implement strict firewall rules and isolate the affected service from internet exposure.
- Increase monitoring and logging for signs of unexpected privilege changes or deserialization-related errors.
- Follow Commvault guidance and apply official patches or maintenance releases as soon as they are published.
Frequently asked questions
Is CVE-2026-77092 being actively exploited?
There are no public reports of exploitation of CVE-2026-77092 as of 2026-09-30.
Which Commvault Cloud versions are affected by CVE-2026-77092?
Commvault Cloud releases in the 11.x line are affected: 11.46.0–11.46.19, 11.44.0–11.44.19, 11.40.0–11.40.71 and 11.36.0–11.36.122.
Is there a patch for CVE-2026-77092?
No fixed versions are listed for CVE-2026-77092 in the provided facts; Commvault has not published fixes for the affected 11.x releases in the data supplied.
Does CVE-2026-77092 require authentication?
The available information indicates the issue is a deserialization of untrusted data and does not list a need for authentication to exploit the vulnerability in Commvault Cloud.
References
- nvd.nist.gov/vuln/detail/CVE-2026-77092
- cve.org/CVERecord?id=CVE-2026-77092
- documentation.commvault.com/securityadvisories/CV_2026_07_6.html
- All Commvault CVEs on CVE Radar
- CVEs published in September 2026