Acronis International GmbH

First CVE: Nov 29, 2021Active for: 5 years
188
CVEs Published
More CVEs Published than 79% of tracked CNAs
31.3
Avg CVEs / Year
More Avg CVEs / Year than 77% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 33% of tracked CNAs
0.5%
In CISA KEV
Higher KEV Rate than 85% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Acronis International GmbH as a CNA, 75.5% affect products that Acronis International GmbH develops as a vendor.

75.5%
24.5%
Self-reported: 142Third-party: 46

Of all the CVEs published that affect products developed by Acronis International GmbH, 82.6% are self-published by Acronis International GmbH as a CNA.

82.6%
17.4%
Self-published: 142Published by other CNAs: 30

Trends Over Time

The number and severity of CVEs published by Acronis International GmbH over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 29, 2021
4 years ago
Most Recent CVE
Jun 3, 2026
51 days ago

Top CVEs

All CVEs published by Acronis International GmbH as a CNA, regardless of affected vendor or product.

188 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructur
Jul 24, 20249.895YESYES
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, L
May 3, 20238.841NOYES
Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Ba
May 3, 20237.536NOYES
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acroni
Feb 20, 202610.035NONO
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acroni
Feb 20, 202610.035NONO
Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis
Feb 20, 202610.034NONO
Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before buil
Feb 20, 20269.834NONO
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Mar 6, 20269.832NONO
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93
Jun 3, 20267.331NONO
Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Clo
Apr 29, 20267.831NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA188 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local116 (61.7%)
Network63 (33.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network9 (4.8%)
Attack Complexity
Low166 (88.3%)
High22 (11.7%)
Unknown0 (0.0%)
User Interaction
None134 (71.3%)
Unknown0 (0.0%)
Required54 (28.7%)
Privileges Required
Low122 (64.9%)
High6 (3.2%)
None60 (31.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (188 CVEs).

CISA KEV
1 CVE
0.5% of CVEs· 85th percentile
Metasploit
3 CVEs
1.6% of CVEs· 90th percentile
Nuclei
1 CVE
0.5% of CVEs· 76th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Acronis International GmbH as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Acronis International GmbH as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs