Acronis International GmbH
Self-Reporting Analysis
Of all the CVEs published by Acronis International GmbH as a CNA, 75.5% affect products that Acronis International GmbH develops as a vendor.
Of all the CVEs published that affect products developed by Acronis International GmbH, 82.6% are self-published by Acronis International GmbH as a CNA.
Trends Over Time
The number and severity of CVEs published by Acronis International GmbH over time
Top CVEs
All CVEs published by Acronis International GmbH as a CNA, regardless of affected vendor or product.
188 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45249CRITICAL Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructur | Jul 24, 2024 | 9.8 | 95 | YES | YES |
CVE-2022-3405HIGH Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, L | May 3, 2023 | 8.8 | 41 | NO | YES |
CVE-2022-30995HIGH Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Ba | May 3, 2023 | 7.5 | 36 | NO | YES |
CVE-2025-30412CRITICAL Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acroni | Feb 20, 2026 | 10.0 | 35 | NO | NO |
CVE-2025-30411CRITICAL Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acroni | Feb 20, 2026 | 10.0 | 35 | NO | NO |
CVE-2025-30416CRITICAL Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis | Feb 20, 2026 | 10.0 | 34 | NO | NO |
CVE-2025-30410CRITICAL Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before buil | Feb 20, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-28710CRITICAL Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | Mar 6, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-42061HIGH Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93 | Jun 3, 2026 | 7.3 | 31 | NO | NO |
CVE-2026-41220HIGH Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Clo | Apr 29, 2026 | 7.8 | 31 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (188 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Acronis International GmbH as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Acronis International GmbH as a CNA — matched by CVE ID, not by organization name.