top of page
perceptive_background_267k.jpg

An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers with Administrator privil…

Published:

2 maart 2026 om 23:00:00

Alert date:

3 maart 2026 om 22:05:24

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Database & Storage

CVE-2025-63910 is an authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614. The vulnerability allows attackers with Administrator privileges to execute arbitrary code by uploading a crafted patch file. This represents a high-severity security flaw that could lead to complete system compromise when exploited by privileged users. The vulnerability affects the file upload mechanism in the migration appliance, potentially allowing malicious code execution through specially crafted patch files.

Technical details

Mitigation steps:

Affected products:

Cohesity TranZman Migration Appliance

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page