Vulnerabilities in Acronis

193 results
Vexday analysis

Com 192 CVEs catalogadas, o portfólio de vulnerabilidades da Acronis apresenta uma taxa de exploração ativa acima da média geral do catálogo CISA KEV — proporção 1,2 vezes superior ao índice de referência —, o que indica atenção redobrada para equipes de resposta a incidentes. A CVE mais crítica em exploração confirmada é a CVE-2023-45249, com score EPSS de 0,5354, sugerindo probabilidade relevante de tentativas de exploração observadas em ambiente real. O tipo de falha mais recorrente é CWE-427 (uncontrolled search path element), classe que frequentemente permite escalonamento de privilégios ou execução de código por meio de dependências mal controladas. As 11 CVEs surgidas nos últimos 90 dias e as 8 de severidade crítica reforçam a necessidade de ciclos de patching ágeis para produtos Acronis em ambientes corporativos.

CVE-2025-30413MEDIUMCredentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud AgentEPSS 0.2%CVE-2026-28709MEDIUMUnauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (LinuEPSS 0.2%CVE-2024-34011MEDIUMLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.2%CVE-2022-44745MEDIUMSensitive information leak through log files. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build EPSS 0.2%CVE-2023-2355MEDIUMLocal privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before bEPSS 0.2%CVE-2024-49385MEDIUMSensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) beforEPSS 0.1%CVE-2022-45455MEDIUMLocal privilege escalation due to incomplete uninstallation cleanup. The following products are affected: Acronis Cyber Protect Home Office EPSS 0.1%CVE-2024-34018MEDIUMSensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) befoEPSS 0.1%CVE-2024-8766MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2025-48963HIGHLocal privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Cloud Agent (LinuxEPSS 0.1%CVE-2023-41751MEDIUMSensitive information disclosure due to improper token expiration validation. The following products are affected: Acronis Agent (Windows) bEPSS 0.1%CVE-2024-49391MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before buiEPSS 0.1%CVE-2024-34017MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before buiEPSS 0.1%CVE-2022-44746LOWSensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office EPSS 0.1%CVE-2024-34019MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before buiEPSS 0.1%CVE-2024-49389HIGHLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files (Windows) before buiEPSS 0.1%CVE-2023-41744HIGHLocal privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Agent (macOS) befEPSS 0.1%CVE-2025-48961HIGHLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Windows) beforEPSS 0.1%CVE-2025-24830MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%CVE-2025-24828MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.1%