Vulnerabilities
167 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-28728 | Local privilege escalation due to DLL hijacking vulnerability. Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902. NVD description · AI analysis pending | 6.7 | <1% |
| — | ||
| CVE-2026-28727 | Local privilege escalation due to insecure Unix socket permissions. Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124, Acronis True Image (macOS) before build 42902. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2026-28710 | Sensitive information disclosure and manipulation due to improper authentication. Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2025-30411 | Sensitive data disclosure and manipulation due to improper authentication. Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800. NVD description · AI analysis pending | 10.0 | <1% |
| — | ||
| CVE-2024-55543 | Local privilege escalation due to DLL hijacking vulnerability. Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2024-49389 | Local privilege escalation due to insecure folder permissions. Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2024-49388 | Sensitive information manipulation due to improper authorization. Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690. NVD description · AI analysis pending | 9.1 group max | <1% |
| — | ||
| CVE-2024-34019 | Local privilege escalation due to DLL hijacking vulnerability. Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 4569. NVD description · AI analysis pending | 7.3 group max | <1% |
| — | ||
| CVE-2023-45249 | Default-Password Remote Command Execution in Acronis Cyber Infrastructure CVE-2023-45249 is an insecure default password flaw (CWE-1393) in Acronis Cyber Infrastructure (ACI) that allows unauthenticated remote command execution with a CVSS 3.1 score of 9.8. An attacker who can reach the exposed service over the network can authenticate with credentials left at vendor defaults and run arbitrary commands, gaining full confidentiality, integrity, and availability impact on the host. Organizations running ACI 5.0, 5.1, 5.2, 5.3, or 5.4 on builds earlier than the fixed builds are affected, particularly deployments where the ACI management interface is internet-facing. The flaw is actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-29 and multiple security outlets reported in-the-wild exploitation, with an EPSS of 53.3% (99th percentile). No public proof-of-concept is known, but exploitation activity has been observed directly. Do: Upgrade each affected ACI deployment to the fixed build for its branch: at least 5.0.1-61, 5.1.1-71, 5.2.1-69, 5.3.1-53, or 5.4.4-132 respectively. Immediately change any account or service passwords still set to vendor defaults, and restrict internet exposure of the ACI management interface. Per CISA's KEV required action, apply vendor mitigations (or discontinue use if unavailable), and review logs for signs of unauthorized access or command execution. | 9.8 | 53% | KEV |
| moderateon the order of 1,000-10,000 exposed ACI instances (estimate) | |
| CVE-2022-45449 | Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2024-34012 | Local privilege escalation due to insecure folder permissions. Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.24135.272. NVD description · AI analysis pending | 4.4 | <1% |
| — | ||
| CVE-2023-48681 +1 in the same advisory: …48682 | Self cross-site scripting (XSS) vulnerability in storage nodes search field. Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391. NVD description · AI analysis pending | 6.1 group max | <1% |
| — |