Vulnerabilities in Acronis

193 results
Vexday analysis

Com 192 CVEs catalogadas, o portfólio de vulnerabilidades da Acronis apresenta uma taxa de exploração ativa acima da média geral do catálogo CISA KEV — proporção 1,2 vezes superior ao índice de referência —, o que indica atenção redobrada para equipes de resposta a incidentes. A CVE mais crítica em exploração confirmada é a CVE-2023-45249, com score EPSS de 0,5354, sugerindo probabilidade relevante de tentativas de exploração observadas em ambiente real. O tipo de falha mais recorrente é CWE-427 (uncontrolled search path element), classe que frequentemente permite escalonamento de privilégios ou execução de código por meio de dependências mal controladas. As 11 CVEs surgidas nos últimos 90 dias e as 8 de severidade crítica reforçam a necessidade de ciclos de patching ágeis para produtos Acronis em ambientes corporativos.

CVE-2025-24832MEDIUMArbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: AcronisEPSS 0.2%CVE-2022-30695Local privilege escalation due to excessive permissions assigned to child processesEPSS 0.2%CVE-2022-44747LOWLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (WindoEPSS 0.2%CVE-2025-24831MEDIUMLocal privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud AgentEPSS 0.2%CVE-2026-33092HIGHLocal privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (mEPSS 0.2%CVE-2026-28724MEDIUMUnauthorized data access due to insufficient access control validation. The following products are affected: Acronis Cyber Protect 17 (LinuxEPSS 0.2%CVE-2024-55538MEDIUMSensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before buildEPSS 0.2%CVE-2023-41750LOWSensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) beEPSS 0.2%CVE-2026-28726MEDIUMSensitive information disclosure due to improper access control. The following products are affected: Acronis Cyber Protect 17 (Linux, WindoEPSS 0.2%CVE-2025-11178HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before builEPSS 0.2%CVE-2025-30408MEDIUMLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.2%CVE-2023-48680LOWSensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber ProteEPSS 0.2%CVE-2023-45241MEDIUMSensitive information leak through log files. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows)EPSS 0.2%CVE-2023-44213LOWSensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber ProteEPSS 0.2%CVE-2024-34016MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.2%CVE-2026-28713HIGHDefault credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud AgeEPSS 0.2%CVE-2022-44744LOWLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (WindoEPSS 0.2%CVE-2022-46868MEDIUMLocal privilege escalation during recovery due to improper soft link handling. The following products are affected: Acronis Cyber Protect HoEPSS 0.2%CVE-2026-28719MEDIUMUnauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (LinuEPSS 0.2%CVE-2023-2782MEDIUMSensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) befoEPSS 0.2%