ZeroHour

Vulnerabilities

167 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-28728
+2 in the same advisory: …27774 …33271
Local privilege escalation due to DLL hijacking vulnerability.

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902.

NVD description · AI analysis pending
6.7<1%
  • acronis true image
CVE-2026-28727
Local privilege escalation due to insecure Unix socket permissions.

Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124, Acronis True Image (macOS) before build 42902.

NVD description · AI analysis pending
7.8
group max
<1%
  • acronis agent
  • acronis cyber protect
CVE-2026-28710
Sensitive information disclosure and manipulation due to improper authentication.

Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

NVD description · AI analysis pending
9.8
group max
<1%
  • acronis cyber protect
CVE-2025-30411
+2 in the same advisory: …30412 …30416
Sensitive data disclosure and manipulation due to improper authentication.

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.

NVD description · AI analysis pending
10.0<1%
  • acronis cyber protect
CVE-2024-55543
+2 in the same advisory: …55540 …55541
Local privilege escalation due to DLL hijacking vulnerability.

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.

NVD description · AI analysis pending
7.8
group max
<1%
  • acronis cyber protect
CVE-2024-49389
+4 in the same advisory: …49390 …49391 …49386 …49392
Local privilege escalation due to insecure folder permissions.

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.

NVD description · AI analysis pending
7.8
group max
<1%
  • acronis cyber files
CVE-2024-49388
+4 in the same advisory: …49387 …49384 …49383 …49382
Sensitive information manipulation due to improper authorization.

Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

NVD description · AI analysis pending
9.1
group max
<1%
  • acronis cyber protect
CVE-2024-34019
+2 in the same advisory: …34017 …34018
Local privilege escalation due to DLL hijacking vulnerability.

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569.

NVD description · AI analysis pending
7.3
group max
<1%
  • acronis snap deploy
CVE-2023-45249
Default-Password Remote Command Execution in Acronis Cyber Infrastructure

CVE-2023-45249 is an insecure default password flaw (CWE-1393) in Acronis Cyber Infrastructure (ACI) that allows unauthenticated remote command execution with a CVSS 3.1 score of 9.8. An attacker who can reach the exposed service over the network can authenticate with credentials left at vendor defaults and run arbitrary commands, gaining full confidentiality, integrity, and availability impact on the host. Organizations running ACI 5.0, 5.1, 5.2, 5.3, or 5.4 on builds earlier than the fixed builds are affected, particularly deployments where the ACI management interface is internet-facing. The flaw is actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-29 and multiple security outlets reported in-the-wild exploitation, with an EPSS of 53.3% (99th percentile). No public proof-of-concept is known, but exploitation activity has been observed directly.

Do: Upgrade each affected ACI deployment to the fixed build for its branch: at least 5.0.1-61, 5.1.1-71, 5.2.1-69, 5.3.1-53, or 5.4.4-132 respectively. Immediately change any account or service passwords still set to vendor defaults, and restrict internet exposure of the ACI management interface. Per CISA's KEV required action, apply vendor mitigations (or discontinue use if unavailable), and review logs for signs of unauthorized access or command execution.

9.853% KEV
  • Acronis Cyber Infrastructure (ACI) all builds before 5.0.1-61
  • Acronis Cyber Infrastructure (ACI) all builds before 5.1.1-71
  • Acronis Cyber Infrastructure (ACI) all builds before 5.2.1-69
  • +2 more
moderateon the order of 1,000-10,000 exposed ACI instances (estimate)
CVE-2022-45449
Sensitive information disclosure due to excessive privileges assigned to Acronis Agent.

Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.

NVD description · AI analysis pending
6.5<1%
  • acronis cyber protect
CVE-2024-34012
Local privilege escalation due to insecure folder permissions.

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.24135.272.

NVD description · AI analysis pending
4.4<1%
  • acronis cloud manager
CVE-2023-48681
+1 in the same advisory: …48682
Self cross-site scripting (XSS) vulnerability in storage nodes search field.

Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.

NVD description · AI analysis pending
6.1
group max
<1%
  • acronis cyber protect