Acronis
Acronis Cyber Protect: vulnerabilidades y CVE
Acronis Cyber Protect tiene 91 vulnerabilidades publicadas, 24 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE91
Últimos 12 meses24
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-28727 | Alta (7.8) | 0.15% | — | 6 mar 2026 | Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124,… |
| CVE-2026-28726 | Media (4.3) | 0.28% | — | 6 mar 2026 | Sensitive information disclosure due to improper access control. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. |
| CVE-2026-28725 | Media (5.5) | 0.16% | — | 6 mar 2026 | Sensitive information disclosure due to improper configuration of a headless browser. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. |
| CVE-2026-28724 | Media (4.3) | 0.28% | — | 6 mar 2026 | Unauthorized data access due to insufficient access control validation. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. |
| CVE-2026-28723 | Media (4.3) | 0.27% | — | 6 mar 2026 | Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. |
| CVE-2026-28722 | Alta (7.3) | 0.16% | — | 6 mar 2026 | Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. |
| CVE-2026-28721 | Alta (7.3) | 0.16% | — | 6 mar 2026 | Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. |
| CVE-2026-28720 | Media (4.3) | 0.27% | — | 6 mar 2026 | Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. |
| CVE-2026-28719 | Media (4.3) | 0.27% | — | 6 mar 2026 | Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. |
| CVE-2026-28718 | Alta (7.5) | 0.64% | — | 6 mar 2026 | Denial of service due to insufficient input validation in authentication logging. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. |
| CVE-2026-28717 | Media (5) | 0.13% | — | 6 mar 2026 | Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. |
| CVE-2026-28716 | Media (4.4) | 0.14% | — | 6 mar 2026 | Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. |
| CVE-2026-28715 | Media (6.5) | 0.36% | — | 6 mar 2026 | Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. |
| CVE-2026-28714 | Media (4.8) | 0.19% | — | 6 mar 2026 | Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. |
| CVE-2026-28713 | Alta (7.1) | 0.29% | — | 6 mar 2026 | Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud Agent (VMware) before build 36943, Acronis Cyber Protect 17 (VMware) before build… |
| CVE-2026-28712 | Media (6.3) | 0.13% | — | 6 mar 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. |
| CVE-2026-28711 | Media (6.3) | 0.13% | — | 6 mar 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186. |
| CVE-2026-28710 | Crítica (9.8) | 0.63% | — | 6 mar 2026 | Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. |
| CVE-2026-28709 | Media (4.3) | 0.27% | — | 6 mar 2026 | Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. |
| CVE-2025-30413 | Media (4.4) | 0.16% | — | 6 mar 2026 | Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40497, Acronis Cyber Protect 17 (Linux,… |
| CVE-2025-11791 | Alta (7.1) | 0.10% | — | 6 mar 2026 | Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186, Acronis Cyber Protect… |
| CVE-2025-30416 | Crítica (10) | 0.46% | — | 20 feb 2026 | Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows)… |
| CVE-2025-30412 | Crítica (10) | 0.71% | — | 20 feb 2026 | Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows)… |
| CVE-2025-30411 | Crítica (10) | 0.80% | — | 20 feb 2026 | Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows)… |
| CVE-2025-48960 | Media (5.9) | 0.08% | — | 4 jun 2025 | Weak server key used for TLS encryption. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938. |
| CVE-2025-30415 | Alta (7.5) | 0.37% | — | 4 jun 2025 | Denial of service due to improper handling of malformed input. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40077, Acronis Cyber Protect 17 (Linux, macOS,… |
| CVE-2024-56414 | Media (5.5) | 0.11% | — | 2 ene 2025 | Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169. |
| CVE-2024-55543 | Alta (7.8) | 0.17% | — | 2 ene 2025 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169. |
| CVE-2024-55541 | Media (6.1) | 0.29% | — | 2 ene 2025 | Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169. |
| CVE-2024-55540 | Alta (7.8) | 0.17% | — | 2 ene 2025 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.