Over the years, we have heard from members of our Community requesting easier and more predictable ways to stay informed about security advisories, CVEs, and updates. Following the recent launch of our new Security Center, Commvault is pleased to roll out a new, standardized monthly cadence for security advisories and updates.
Beginning Tuesday, August 11, Commvault will issue security patches and related advisories on the second Tuesday of each month (also known as “Patch Tuesdays”), providing customers with a predictable schedule for planning and implementing security updates. This consistent rhythm is important as the pace of vulnerability discovery continues to accelerate and will help customers and partners stay informed, prepared, and resilient in an evolving threat landscape.
Recommended Actions & What to Know
To ensure you receive timely notifications, take a moment to review your profile and alert preferences in the Commvault Support Portal and confirm that you are subscribed to Security Advisory Alerts.
Just log in to the Support Portal and click on your profile in the upper right corner. Then, select “Product and alert information” in the left navigation. Verify your email address for alerts distribution and make sure you have selected “Yes” to “Receive Commvault Cloud Security Advisory Alerts” along with Critical Alert Messages, Feature & Maintenance Release Alert Messages, and other relevant product alerts.

Once you are subscribed, Commvault will automatically provide advance notification of upcoming security updates, remediation guidance, and recommended actions. Customers can expect to receive alert communications seven days before public CVE disclosure whenever applicable. Public disclosures will occur on the second Tuesday of each month (or off schedule where required).
Commvault Cloud SaaS Customers
Commvault SaaS services are updated automatically with the latest security fixes. SaaS customers should only need to review the advisories and verify that their environments and installations are current.
Self-Hosted Software Customers
Customers running self-hosted Commvault software must install the latest software version and security patches. We recommend reviewing monthly security advisories and implementing updates as soon as possible to address disclosed vulnerabilities.
If you have questions about your environment, update strategy, or remediation plans, please contact your Customer Success team, Technical Account Manager (TAM), or Partner Business Manager (PBM).
Related Resources to Bookmark
- Support Portal Resource page for CVE Advisories and Maintenance Packs. This page aggregates step-by-step guidance to help identify your version, download and apply the correct Maintenance Release Pack, and FAQs.
- Commvault Security Center. This new site brings together the latest security research, insights, and threat guidance from Commvault's security team.
- Commvault Cloud Security Advisories page
- (Blog) Bringing Trust to CVE Disclosures. Commvault Chief Security Officer Bill O’Connell shares perspective on why organizations everywhere need to re-examine vulnerability management processes and why we are introducing the Patch Tuesdays cadence.
- (Blog) Anatomy of a CVE: How Commvault Protects Its Customers
- Commvault Trust Center. Find details on Commvault’s Certifications, Compliances, and audit reports.

