Security Research & Guidance
Security Center
Security research and threat guidance from Commvault's security team. For full CVE disclosures and technical advisories, visit our Security Advisories documentation.
The Landscape
What's changed in how vulnerabilities are found and disclosed?
Discovery is faster
Close to 48,000 CVEs were published in 2025, roughly 130 a day.
The old signal is thinning
The National Vulnerability Database has moved to selective, risk-based processing.
The window is closing
Working exploit code can now appear before a patch is widely deployed.
From the Security Center
Start your journey here
Blog: The Window Between Discovery And Exploit Is Closing
The rapid growth in vulnerabilities and AI-enabled discovery is shrinking the time between vulnerability disclosure and active exploitation.
Read the blog
Blog: The Anatomy of a CVE: How Commvault Protects Its Customers
A CVE is a globally unique identifier for a publicly disclosed software vulnerability, enabling vendors, researchers, and defenders to reference the same flaw consistently.
Read the blog
Blog: JadePuffer: What Agentic Ransomware Means for Recovery
An AI agent chained known vulnerabilities into a destructive extortion campaign, with minimal hands-on-keyboard involvement once the operation was underway
Read the blog
Blog: What OpenAI's Hugging Face Security Incident Means for Cyber Resilience
An OpenAI evaluation unexpectedly became a real-world security incident after advanced AI models exploited vulnerabilities, escaped their test environment, and compromised Hugging Face infrastructure.
Read the blog
Blog: When the Risk Comes From Outside: How Commvault Responds to Third-Party Incidents
Modern businesses connect a growing web of third-party applications to their core platforms. Each of these connections adds value – and risk.
Read the blog
Trust & Compliance
Backed by independent certification
Our compliance posture is documented and independently audited. View our full certifications and assurance documentation in the Trust Center.
More Security Content
Explore more security content
The four attack vectors your AI security framework isn't built for
Most AI security frameworks were built for yesterday’s threats. Here’s what they’re missing.
Your identity infrastructure is a target
Identity systems are now a primary attack surface. See how Commvault helps you detect and recover from identity-based attacks.
Are you ready for the industrialized vishing attack?
Voice phishing has scaled into an industry. Here’s how to recognize and defend against it.
Fortifying your core: a modern approach to Active Directory resilience
Active Directory sits at the center of most enterprise attacks. Here’s a modern approach to protecting it.
MCP 2.0 explained: securing AI agents before they secure themselves
AI agents can act before anyone reviews them. Here’s how MCP 2.0 helps secures agents before they secure themselves.
AI security risk analysis: MCP 2.0
A closer look at where MCP 2.0 introduces risk, and what security teams should evaluate first.
Frequently Asked Questions
What is Commvault doing around AI-assisted security testing?
We actively evaluate our products using AI-assisted methods as part of our structured security engineering program, in Commvault-controlled environments, under the same governance as every other form of testing.
How is Commvault preparing for AI-driven vulnerability discovery?
Our program is model-agnostic and tool-agnostic by design, so we can incorporate new methods inside one consistent governance framework.
Is Commvault using these models safely?
Yes. All evaluation happens on isolated hardware or Commvault-managed cloud infrastructure. Source code never leaves our boundaries, and every AI-generated finding requires human confirmation before action.
How is Commvault scaling vulnerability management for the AI era?
We’re investing in risk-based triage and remediation infrastructure so the response process can scales with discovery volume, not just the discovery itself.