---
title: "Security Center | Threat Guidance & Research | Commvault "
type: "WebPage"
language: "en-US"
url: "https://www.commvault.com/security-center"
date: "2026-07-08T09:37:26-04:00"
modified: "2026-08-11T09:17:22-04:00"
description: "Security Center | Commvault: How we evaluate and respond to threats. "
image: "https://www.commvault.com/wp-content/uploads/2026/07/security-center-header.jpg"
breadcrumbs:
  - name: "Commvault Home"
    url: "https://www.commvault.com/"
  - name: "Security center"
---

# Security Center

- [Home](/)
- Security Center

Security Research & Guidance

## Security Center

Security research and threat guidance from Commvault's security team. For full CVE disclosures and technical advisories, visit our Security Advisories documentation.

- [View security advisories](http://documentation.commvault.com/securityadvisories)

![](/wp-content/uploads/2026/07/security-center-header.jpg)

---

The Landscape

## What's changed in how vulnerabilities are found and disclosed?

![](https://www.commvault.com/wp-content/uploads/2025/08/Actionable-Data_Crocus_RGB_f2d1ec-2.svg)

---

## Discovery is faster

Close to 48,000 CVEs were published in 2025, roughly 130 a day.

![](https://www.commvault.com/wp-content/uploads/2025/08/Archive_Crocus_RGB_e0ddbc.svg)

---

## The old signal is thinning

The National Vulnerability Database has moved to selective, risk-based processing.

![](https://www.commvault.com/wp-content/uploads/2025/08/Domain-Org-2_Crocus_RGB-1.svg)

---

## The window is closing

Working exploit code can now appear before a patch is widely deployed.

---

From the Security Center

## Start your journey here

BLOG

AI & Innovation

## The Window Between Discovery And Exploit Is Closing

The rapid growth in vulnerabilities and AI-enabled discovery is shrinking the time between vulnerability disclosure and active exploitation.

**Rajiv Kottomtharayil**, Chief Products Officer, Commvault

[Read the blog about The Window Between Discovery And Exploit Is Closing](https://www.commvault.com/blogs/the-window-between-discovery-and-exploit-is-closing)

BLOG

Cyber Resilience & Data Security

## The Anatomy of a CVE: How Commvault Protects Its Customers

A CVE is a globally unique identifier for a publicly disclosed software vulnerability, enabling vendors, researchers, and defenders to reference the same flaw consistently.

**Werner Nel**, Principal Product Experience, Commvault

[Read the blog about The Anatomy of a CVE: How Commvault Protects Its Customers](https://www.commvault.com/blogs/the-anatomy-of-a-cve-how-commvault-protects-its-customers)

---

Learn more

## Browse the latest security articles

Blog: How Commvault Leverages Frontier AI to Strengthen Software

AI accelerates vulnerability discovery, while disciplined security processes drive remediation.

[Read the blog](/blogs/how-commvault-leverages-frontier-ai-to-strengthen-software)

Blog: Bringing Trust to CVE Disclosures

Starting August 11, 2026, Commvault is changing how we disclose vulnerabilities in the Frontier AI era.

[Read the blog](/blogs/bringing-trust-to-cve-disclosures)

Blog: JadePuffer: What Agentic Ransomware Means for Recovery

An AI agent chained known vulnerabilities into a destructive extortion campaign, with minimal hands-on-keyboard involvement once the operation was underway

[Read the blog](/blogs/sysdig-calls-jadepuffer-the-first-documented-agentic-ransomware-attack)

Blog: What OpenAI's Hugging Face Security Incident Means for Cyber Resilience

An OpenAI evaluation unexpectedly became a real-world security incident after advanced AI models exploited vulnerabilities, escaped their test environment, and compromised Hugging Face infrastructure.

[Read the blog](/blogs/openai-hugging-face-security-incident-cyber-resilience)

Blog: When the Risk Comes From Outside: How Commvault Responds to Third-Party Incidents

Modern businesses connect a growing web of third-party applications to their core platforms. Each of these connections adds value – and risk.

[Read the blog](/blogs/how-commvault-responds-to-third-party-incidents)

![](/wp-content/uploads/2025/08/SupportedTech_Microsoft_Benefits_ProvenResiliency_1088x870-2.jpg)

---

Trust & Compliance

## Backed by independent certification

Our compliance posture is documented and independently audited. View our full certifications and assurance documentation in the Trust Center.

[Know more](https://trust.commvault.com/)

---

- ![](/wp-content/uploads/2025/08/AICPA-SOC-2-badge-rgb.png)
- ![](/wp-content/uploads/2025/08/widget-badge-fips-140-2.png)
- ![](/wp-content/uploads/2025/08/1_GovRAMP-Prime-Member-Badge.png)
- ![](/wp-content/uploads/2025/08/fedRAMP_High.png)
- ![](/wp-content/uploads/2025/08/widget-badge-vpat-508.png)

---

More Security Content

## Explore more security content

![](/wp-content/uploads/2026/07/Thumbnail_Blog-Post-Quantum-Cryptography-Clock-2026.png)

Security Blog

## The four attack vectors your AI security framework isn't built for

Most AI security frameworks were built for yesterday’s threats. Here’s what they’re missing.

[Read more about The four attack vectors your AI security framework isn't built for](/blogs/the-four-attack-vectors-your-ai-security-framework-isnt-built-for)

![](/wp-content/uploads/2026/05/Thumbnail_Blog-Identity-Resilience-MachineID-2026-Linkedin.png)

Security Blog

## Your identity infrastructure is a target

Identity systems are now a primary attack surface. See how Commvault helps you detect and recover from identity-based attacks.

[Read more about Your identity infrastructure is a target](/blogs/your-identity-infrastructure-is-a-target)

![](/wp-content/uploads/2026/06/Thumbnail_Blog-Blue-Yonder-2026.png)

Security Blog

## Are you ready for the industrialized vishing attack?

Voice phishing has scaled into an industry. Here’s how to recognize and defend against it.

[Read more about Are you ready for the industrialized vishing attack?](/blogs/are-you-ready-for-the-industrialized-vishing-attack)

![](/wp-content/uploads/2025/08/Thumbnail_Blog_HPE-Active-Peer-Persistence-2024-_1_.png)

Security Blog

## Fortifying your core: a modern approach to Active Directory resilience

Active Directory sits at the center of most enterprise attacks. Here’s a modern approach to protecting it.

[Read more about Fortifying your core: a modern approach to Active Directory resilience](/blogs/fortifying-your-core-a-modern-approach-to-active-directory-resilience)

![](/wp-content/uploads/2026/07/Thumbnail_Blog-Cloud-Native-Backup-Google-2026.png)

AI Governance Blog

## MCP 2.0 explained: securing AI agents before they secure themselves

AI agents can act before anyone reviews them. Here’s how MCP 2.0 helps secures agents before they secure themselves.

[Read more about MCP 2.0 explained: securing AI agents before they secure themselves](/blogs/mcp-2-0-explained-securing-ai-agents-before-they-secure-themselves)

![](/wp-content/uploads/2026/05/pexels-mahmoudramadan-31622922-scaled.jpg)

AI Governance Report

## AI security risk analysis: MCP 2.0

A closer look at where MCP 2.0 introduces risk, and what security teams should evaluate first.

[Read more about AI security risk analysis: MCP 2.0](http://readiverse.com/readiness-report/mcp)

---

## Frequently Asked Questions

What is Commvault doing around AI-assisted security testing?

We actively evaluate our products using AI-assisted methods as part of our structured security engineering program, in Commvault-controlled environments, under the same governance as every other form of testing.

How is Commvault preparing for AI-driven vulnerability discovery?

Our program is model-agnostic and tool-agnostic by design, so we can incorporate new methods inside one consistent governance framework.

Is Commvault using these models safely?

Yes. All evaluation happens on isolated hardware or Commvault-managed cloud infrastructure. Source code never leaves our boundaries, and every AI-generated finding requires human confirmation before action.

How is Commvault scaling vulnerability management for the AI era?

We’re investing in risk-based triage and remediation infrastructure so the response process can scales with discovery volume, not just the discovery itself.

---

## Have a question about an advisory, or something to report?

Browse our security advisories, or reach our team directly.

[View security advisories](http://documentation.commvault.com/securityadvisories) [Report a vulnerability](https://documentation.commvault.com/securityadvisories/report.html)

![](/wp-content/uploads/2025/11/home-cleanroom-final-421x455-1.png)
