Skip to main content
Question

Advisory ID: CV_2026_07_5 , CV_2026_07_8 and CV_2026_07_9

  • August 4, 2026
  • 3 replies
  • 78 views

Forum|alt.badge.img+3

We will eventually upgrade everything to 11.36.114 but what needs this update in order to resolve these vulnerabilities?

Is it just the CommServe/WebServer?

The Resolution does not state what needs to be updated.
“Resolution
Software customers upgrade to resolved maintenance release.”

https://documentation.commvault.com/upcoming-security-advisories/?id=CV_2026_07_5 https://documentation.commvault.com/upcoming-security-advisories/?id=CV_2026_07_8 https://documentation.commvault.com/upcoming-security-advisories/?id=CV_2026_07_9

 

 

Thanks

3 replies

Forum|alt.badge.img+17
  • Vaulter
  • August 5, 2026

HI ​@Nick ,

If the CommServe and Web Server are hosted on the same machine, it is recommended to install the fix on that server. If they are hosted on separate machines, the fix may need to be installed on both the CommServe and the Web Server to ensure the issue is fully addressed.


Forum|alt.badge.img
  • Novice
  • August 5, 2026

If the agents remain on 11.36.98 and are not upgraded to 11.36.114, does that mean they are still vulnerable?

The reason I'm asking is that we're planning to move to 11.44, but we're not quite ready for that upgrade yet. As an interim measure, we're considering upgrading only the Commvault infrastructure components to 11.36.114 while leaving the agents on 11.36.98.

Would the agents still be affected by the vulnerability in that scenario, or is upgrading the infrastructure components sufficient?


Forum|alt.badge.img+17
  • Vaulter
  • August 6, 2026

Hi ​@quartzblu ,

If the above CVE were found on Commserv server then upgrading Commserv machine to 11.36.114 is sufficient there is no need to upgrade the agents.