Vulnerabilities in Acronis

193 results
Vexday analysis

Com 192 CVEs catalogadas, o portfólio de vulnerabilidades da Acronis apresenta uma taxa de exploração ativa acima da média geral do catálogo CISA KEV — proporção 1,2 vezes superior ao índice de referência —, o que indica atenção redobrada para equipes de resposta a incidentes. A CVE mais crítica em exploração confirmada é a CVE-2023-45249, com score EPSS de 0,5354, sugerindo probabilidade relevante de tentativas de exploração observadas em ambiente real. O tipo de falha mais recorrente é CWE-427 (uncontrolled search path element), classe que frequentemente permite escalonamento de privilégios ou execução de código por meio de dependências mal controladas. As 11 CVEs surgidas nos últimos 90 dias e as 8 de severidade crítica reforçam a necessidade de ciclos de patching ágeis para produtos Acronis em ambientes corporativos.

CVE-2021-44198DLL hijacking could lead to local privilege escalationEPSS 0.3%CVE-2026-87886HIGHLocal privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (LiEPSS 0.3%KEVCVE-2022-45454LOWSensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before buiEPSS 0.3%CVE-2023-44210HIGHSensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect CEPSS 0.2%CVE-2023-44209MEDIUMLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Cloud Agent (LinuxEPSS 0.2%CVE-2023-48677HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (WindoEPSS 0.2%CVE-2023-44212HIGHSensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Agent (Linux, mEPSS 0.2%CVE-2023-45248MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.2%CVE-2022-30696Local privilege escalation due to a DLL hijacking vulnerabilityEPSS 0.2%CVE-2024-49386MEDIUMSensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0EPSS 0.2%CVE-2021-44206Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder serviceEPSS 0.2%CVE-2023-44161LOWSensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, EPSS 0.2%CVE-2021-44205Local privilege escalation due to DLL hijacking vulnerabilityEPSS 0.2%CVE-2023-44211HIGHSensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect CEPSS 0.2%CVE-2023-44160LOWSensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, EPSS 0.2%CVE-2022-46869HIGHLocal privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber ProtecEPSS 0.2%CVE-2025-48962MEDIUMSensitive information disclosure due to SSRF. The following products are affected: Acronis Cyber Protect 16 (Windows, Linux) before build 39EPSS 0.2%CVE-2021-44199DLL hijacking could lead to denial of serviceEPSS 0.2%CVE-2023-45245LOWSensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) beEPSS 0.2%CVE-2024-56413MEDIUMMissing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169EPSS 0.2%