Vulnerabilities in Acronis

193 results
Vexday analysis

Com 192 CVEs catalogadas, o portfólio de vulnerabilidades da Acronis apresenta uma taxa de exploração ativa acima da média geral do catálogo CISA KEV — proporção 1,2 vezes superior ao índice de referência —, o que indica atenção redobrada para equipes de resposta a incidentes. A CVE mais crítica em exploração confirmada é a CVE-2023-45249, com score EPSS de 0,5354, sugerindo probabilidade relevante de tentativas de exploração observadas em ambiente real. O tipo de falha mais recorrente é CWE-427 (uncontrolled search path element), classe que frequentemente permite escalonamento de privilégios ou execução de código por meio de dependências mal controladas. As 11 CVEs surgidas nos últimos 90 dias e as 8 de severidade crítica reforçam a necessidade de ciclos de patching ágeis para produtos Acronis em ambientes corporativos.

CVE-2026-28723MEDIUMUnauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Protect 17 (Linux, WindoEPSS 0.2%CVE-2026-28720MEDIUMUnauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 1EPSS 0.2%CVE-2026-28714MEDIUMUnnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows)EPSS 0.2%CVE-2024-55543HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) beforEPSS 0.2%CVE-2024-55540MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) beforEPSS 0.2%CVE-2024-55542MEDIUMLocal privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are affected: Acronis CyberEPSS 0.2%CVE-2024-49390HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before buiEPSS 0.2%CVE-2024-49387MEDIUMCleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (LiEPSS 0.2%CVE-2022-44732HIGHLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (WindoEPSS 0.2%CVE-2022-24115Local privilege escalation due to unrestricted loading of unsigned librariesEPSS 0.2%CVE-2023-48684HIGHSensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect CEPSS 0.2%CVE-2023-48683HIGHSensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect CEPSS 0.2%CVE-2023-48678MEDIUMSensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, WEPSS 0.2%CVE-2023-44214MEDIUMSensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) beEPSS 0.2%CVE-2022-45452HIGHLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 304EPSS 0.2%CVE-2023-45242MEDIUMSensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (LinuxEPSS 0.2%CVE-2023-45240MEDIUMSensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) beEPSS 0.2%CVE-2026-28721HIGHLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) beforEPSS 0.2%CVE-2026-28722HIGHLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) beforEPSS 0.2%CVE-2022-24114Local privilege escalation due to race condition on application startupEPSS 0.2%