


Perceptive Security
SOC/SIEM Consultancy

Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injection vulnerability.
Published:
2 March 2026 at 23:00:00
Alert date:
3 March 2026 at 22:05:24
Source:
nvd.nist.gov
Enterprise Applications, Database & Storage
CVE-2025-63911 affects Cohesity TranZman Migration Appliance Release 4.0 Build 14614, containing an authenticated command injection vulnerability. This security flaw allows authenticated users to execute arbitrary commands on the affected system. The vulnerability impacts the migration appliance used for data migration operations. Command injection vulnerabilities can lead to complete system compromise when exploited. The issue has been documented with proof-of-concept details available through GitHub repositories.
Technical details
Mitigation steps:
Affected products:
Cohesity TranZman Migration Appliance
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-63911
https://gist.github.com/GregDurys/8b7a3022c04b6cee8c1e1af04f5671b2
https://github.com/GregDurys/Cohesity-TranZman-CVEs
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
