Skip to content

Security Research & Guidance

Security Center

Security research and threat guidance from Commvault's security team. For full CVE disclosures and technical advisories, visit our Security Advisories documentation.

The Landscape

What's changed in how vulnerabilities are found and disclosed?


Discovery is faster

Close to 48,000 CVEs were published in 2025, roughly 130 a day.


The old signal is thinning

The National Vulnerability Database has moved to selective, risk-based processing.


The window is closing

Working exploit code can now appear before a patch is widely deployed.

From the Security Center

Start your journey here

Blog: The Window Between Discovery And Exploit Is Closing

The rapid growth in vulnerabilities and AI-enabled discovery is shrinking the time between vulnerability disclosure and active exploitation.

Read the blog
Blog: The Anatomy of a CVE: How Commvault Protects Its Customers

A CVE is a globally unique identifier for a publicly disclosed software vulnerability, enabling vendors, researchers, and defenders to reference the same flaw consistently.

Read the blog
Blog: JadePuffer: What Agentic Ransomware Means for Recovery

An AI agent chained known vulnerabilities into a destructive extortion campaign, with minimal hands-on-keyboard involvement once the operation was underway

Read the blog
Blog: What OpenAI's Hugging Face Security Incident Means for Cyber Resilience

An OpenAI evaluation unexpectedly became a real-world security incident after advanced AI models exploited vulnerabilities, escaped their test environment, and compromised Hugging Face infrastructure.

Read the blog
Blog: When the Risk Comes From Outside: How Commvault Responds to Third-Party Incidents

Modern businesses connect a growing web of third-party applications to their core platforms. Each of these connections adds value – and risk.

Read the blog

Trust & Compliance

Backed by independent certification

Our compliance posture is documented and independently audited. View our full certifications and assurance documentation in the Trust Center. 

More Security Content

Explore more security content

Security Blog

The four attack vectors your AI security framework isn't built for

Most AI security frameworks were built for yesterday’s threats. Here’s what they’re missing.

Read more about The four attack vectors your AI security framework isn't built for
Security Blog

Your identity infrastructure is a target

Identity systems are now a primary attack surface. See how Commvault helps you detect and recover from identity-based attacks.

Read more about Your identity infrastructure is a target
Security Blog

Are you ready for the industrialized vishing attack?

Voice phishing has scaled into an industry. Here’s how to recognize and defend against it.

Read more about Are you ready for the industrialized vishing attack?
Security Blog

Fortifying your core: a modern approach to Active Directory resilience

Active Directory sits at the center of most enterprise attacks. Here’s a modern approach to protecting it.

Read more about Fortifying your core: a modern approach to Active Directory resilience
AI Governance Blog

MCP 2.0 explained: securing AI agents before they secure themselves

AI agents can act before anyone reviews them. Here’s how MCP 2.0 helps secures agents before they secure themselves. 

Read more about MCP 2.0 explained: securing AI agents before they secure themselves
AI Governance Report

AI security risk analysis: MCP 2.0

A closer look at where MCP 2.0 introduces risk, and what security teams should evaluate first.

Read more about AI security risk analysis: MCP 2.0

Frequently Asked Questions

What is Commvault doing around AI-assisted security testing?

We actively evaluate our products using AI-assisted methods as part of our structured security engineering program, in Commvault-controlled environments, under the same governance as every other form of testing.

How is Commvault preparing for AI-driven vulnerability discovery?

Our program is model-agnostic and tool-agnostic by design, so we can incorporate new methods inside one consistent governance framework.

Is Commvault using these models safely?

Yes. All evaluation happens on isolated hardware or Commvault-managed cloud infrastructure. Source code never leaves our boundaries, and every AI-generated finding requires human confirmation before action.

How is Commvault scaling vulnerability management for the AI era?

We’re investing in risk-based triage and remediation infrastructure so the response process can scales with discovery volume, not just the discovery itself.