VendorsAcroniscyber_protectany version
Vulnerabilities

Acronis Cyber Protect any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

71CVEs
CVE-2026-28710
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Published 2026-03-05 · Analyzed
9.8EPSS 0.006
CVE-2023-44206
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
9.1EPSS 0.008
CVE-2023-44152
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
Published 2023-09-27 · Modified
9.1EPSS 0.006
CVE-2024-49388
Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Published 2024-10-15 · Analyzed
9.1EPSS 0.003
CVE-2023-44154
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
8.1EPSS 0.006
CVE-2020-10138
Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis Cyber Backup and Cyber Protect contain a privileged service that uses this OpenSSL component. Because unprivileged Windows users can create subdirectories off of the system root, a user can create the appropriate path to a specially-crafted openssl.cnf file to achieve arbitrary code execution with SYSTEM privileges.
Published 2020-10-21 · Modified
7.8EPSS 0.005
CVE-2021-38086
Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking.
Published 2021-08-12 · Modified
7.8EPSS 0.003
CVE-2021-44198
DLL hijacking could lead to local privilege escalation
Published 2021-11-29 · Modified
7.8EPSS 0.003
CVE-2021-38088
Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking.
Published 2021-08-12 · Modified
7.8EPSS 0.002
CVE-2023-44157
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 35979.
Published 2023-09-27 · Modified
7.8EPSS 0.002
CVE-2024-55543
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
Published 2025-01-02 · Analyzed
7.8EPSS 0.002
CVE-2024-55540
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
Published 2025-01-02 · Analyzed
7.8EPSS 0.002
CVE-2022-45452
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30430, Acronis Cyber Protect 15 (Windows) before build 30984.
Published 2023-05-18 · Modified
7.8EPSS 0.002
CVE-2026-28727
Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124, Acronis True Image (macOS) before build 42902.
Published 2026-03-05 · Modified
7.8EPSS 0.001
CVE-2022-45449
Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.
Published 2024-07-16 · Analyzed
7.7EPSS 0.004
CVE-2020-35556
An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, information disclosure can occur.
Published 2021-02-22 · Modified
7.5EPSS 0.011
CVE-2022-30990
Sensitive information disclosure due to insecure folder permissions
Published 2022-05-18 · Modified
7.5EPSS 0.009
CVE-2023-44156
Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
7.5EPSS 0.009
CVE-2023-44155
Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
7.5EPSS 0.007
CVE-2023-44158
Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
7.5EPSS 0.006
CVE-2026-28718
Denial of service due to insufficient input validation in authentication logging. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Published 2026-03-05 · Analyzed
7.5EPSS 0.006
CVE-2022-30993
Cleartext transmission of sensitive information
Published 2022-05-18 · Modified
7.5EPSS 0.006
CVE-2022-30994
Cleartext transmission of sensitive information
Published 2022-05-18 · Modified
7.5EPSS 0.006
CVE-2023-44159
Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
7.5EPSS 0.004
CVE-2022-45450
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 30984.
Published 2023-05-18 · Modified
7.5EPSS 0.004
CVE-2022-45457
Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows) before build 29633, Acronis Cyber Protect 15 (Windows) before build 30984.
Published 2023-05-18 · Modified
7.5EPSS 0.004
CVE-2022-45458
Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 29633, Acronis Cyber Protect 15 (Windows, macOS, Linux) before build 30984.
Published 2023-05-18 · Modified
7.5EPSS 0.004
CVE-2022-45459
Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984.
Published 2023-05-18 · Modified
7.5EPSS 0.003
CVE-2022-45453
TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.
Published 2023-05-18 · Modified
7.5EPSS 0.003
CVE-2023-44153
Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
Published 2023-09-27 · Modified
7.5EPSS 0.003
CVE-2024-49387
Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Published 2024-10-15 · Analyzed
7.5EPSS 0.002
CVE-2026-28722
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.
Published 2026-03-05 · Analyzed
7.3EPSS 0.002
CVE-2026-28721
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.
Published 2026-03-05 · Analyzed
7.3EPSS 0.002
CVE-2026-28713
Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud Agent (VMware) before build 36943, Acronis Cyber Protect 17 (VMware) before build 41186.
Published 2026-03-05 · Analyzed
7.1EPSS 0.003
CVE-2025-11791
Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186, Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124.
Published 2026-03-05 · Analyzed
7.1EPSS 0.001
CVE-2023-44207
Stored cross-site scripting (XSS) vulnerability in protection plan name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
6.7EPSS 0.005
CVE-2026-28715
Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Published 2026-03-05 · Analyzed
6.5EPSS 0.003
CVE-2023-44160
Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
6.5EPSS 0.002
CVE-2023-44161
Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
6.5EPSS 0.002
CVE-2026-28712
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.
Published 2026-03-05 · Analyzed
6.3EPSS 0.001
1 / 2Next →