Skip to main content
StickyNews

Security Updates and Advisories: A New Monthly Cadence and Resources

  • August 12, 2026
  • 2 replies
  • 70 views
Jennifer Kelley
Vaulter
Forum|alt.badge.img+20

Over the years, we have heard from members of our Community requesting easier and more predictable ways to stay informed about security advisories, CVEs, and updates. Following the recent launch of our new Security Center, Commvault is pleased to roll out a new, standardized monthly cadence for security advisories and updates. 

Beginning Tuesday, August 11, Commvault will issue security patches and related advisories on the second Tuesday of each month (also known as “Patch Tuesdays”), providing customers with a predictable schedule for planning and implementing security updates. This consistent rhythm is important as the pace of vulnerability discovery continues to accelerate and will help customers and partners stay informed, prepared, and resilient in an evolving threat landscape. 

 

Recommended Actions & What to Know 

To ensure you receive timely notifications, take a moment to review your profile and alert preferences in the Commvault Support Portal and confirm that you are subscribed to Security Advisory Alerts. 

Just log in to the Support Portal and click on your profile in the upper right corner. Then, select “Product and alert information” in the left navigation. Verify your email address for alerts distribution and make sure you have selected “Yes” to “Receive Commvault Cloud Security Advisory Alerts” along with Critical Alert Messages, Feature & Maintenance Release Alert Messages, and other relevant product alerts. 

 

Manage Alert and Notification Preferences in your Support Portal profile

 

Once you are subscribed, Commvault will automatically provide advance notification of upcoming security updates, remediation guidance, and recommended actions. Customers can expect to receive alert communications seven days before public CVE disclosure whenever applicable. Public disclosures will occur on the second Tuesday of each month (or off schedule where required). 

Commvault Cloud SaaS Customers 

Commvault SaaS services are updated automatically with the latest security fixes. SaaS customers should only need to review the advisories and verify that their environments and installations are current.

Self-Hosted Software Customers 

Customers running self-hosted Commvault software must install the latest software version and security patches. We recommend reviewing monthly security advisories and implementing updates as soon as possible to address disclosed vulnerabilities. 

 

If you have questions about your environment, update strategy, or remediation plans, please contact your Customer Success team, Technical Account Manager (TAM), or Partner Business Manager (PBM).
 

Related Resources to Bookmark

 

2 replies

Erase4ndReuseMedia
Community All Star
Forum|alt.badge.img+17

Nice! This will greatly assist in better aligning our existing processes.
 
As part of this initiative, can we also expect better reporting of vulnerabilities within third-party libraries? 

It has been a pain point for us recently - if details are not adequately disclosed via Commvault's Security Advisories, we are now required to raise a support ticket to determine the potential impact, remediation timeframes, etc.


Jennifer Kelley
Vaulter
Forum|alt.badge.img+20

Thanks ​@Erase4ndReuseMedia, we appreciate the thumbs up and the follow-up question.
At the moment, we have a public blog post from the Security team covering how Commvault responds to Third-Party incidents at a high level. I’ll share your more specific question along regarding the security advisories specifically.