{"record":"Cohesity evidence record","url":"https://nexalign.io/vendors/cohesity","vendor":{"slug":"cohesity","name":"Cohesity","domain":"cohesity.com","category":"backup","categoryLabel":"Backup and recovery"},"lastChecked":"2026-07-28T10:17:35.105Z","coverage":{"earliest":"2019-07-12T19:04:51.000Z","latest":"2026-07-14T04:17:26.124Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":16,"kindsOfSource":3,"attributedAdvisories":5,"knownExploited":0,"registerEntriesNotAttributable":5,"practitionerThreads":0,"independentItems":1,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":10,"latest":"2026-03-03T00:00:00.000Z"},{"source":"National Vulnerability Database","operator":"NIST, United States Department of Commerce","classification":"authoritative","items":5,"latest":"2026-03-03T18:16:24.033Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":1,"latest":"2026-07-14T04:17:26.124Z"}],"advisories":{"shown":5,"total":5,"truncated":false,"items":[{"id":"CVE-2025-67840","description":"Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Build 14614 through TZM_1757588060_SEP2025_FULL.depot web application API…","severity":"high","cvss":7.2,"knownExploited":false,"date":"2026-03-03T18:16:24.033Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-67840","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208246"]},{"id":"CVE-2025-63912","description":"Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for data encryption, allowing attackers to trivially reverse the encyption…","severity":"high","cvss":7.5,"knownExploited":false,"date":"2026-03-03T18:16:23.920Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-63912","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208244"]},{"id":"CVE-2025-63911","description":"Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injection vulnerability.","severity":"high","cvss":7.2,"knownExploited":false,"date":"2026-03-03T18:16:23.773Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-63911","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208243"]},{"id":"CVE-2025-63910","description":"An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers with Administrator privileges to execute arbitrary…","severity":"high","cvss":7.2,"knownExploited":false,"date":"2026-03-03T18:16:23.630Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-63910","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208242"]},{"id":"CVE-2025-63909","description":"Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers to escalate privileges to root and…","severity":"high","cvss":7.2,"knownExploited":false,"date":"2026-03-03T18:16:23.480Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-63909","https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-208241"]}]},"practitionerThreads":{"shown":0,"total":0,"truncated":false,"items":[]},"independentCoverage":{"shown":1,"total":1,"truncated":false,"items":[{"title":"Cohesity - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Cohesity","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 5 register entries mention Cohesity without naming a product of Cohesity as affected. They are excluded rather than counted as vulnerabilities.","No public practitioner discussion naming Cohesity was found in the indexed threads. Operational experience with this product is not represented in this record.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}