Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Acronis International GmbH

First CVE: Mar 10, 2008Active for: 18 yearsTotal CVEs: 172
61.3
VTI Score
TOP TARGET

Acronis International GmbH is a cybersecurity and data-protection vendor whose vulnerability footprint spans backup, recovery, and endpoint-protection products deployed across enterprise and consumer segments, including flagship offerings such as Cyber Protect, True Image, and Snap Deploy. The vendor's exposure recurs through a characteristic set of weakness classes including uncontrolled search-path elements, missing authorization checks, incorrect default permissions, and cross-site scripting flaws, reflecting the complexity of privileged agent software and web-based management interfaces that operate with elevated system access. Vulnerabilities affecting this vendor lean toward serious outcomes, with a meaningful share reaching critical severity; the weakness classes that recur—particularly those affecting authentication, authorization, and local privilege escalation—align with the high-trust role these products occupy in the backup and recovery chain. Defenders deploying Acronis products should prioritize agent and management-console updates and enforce strict access controls around backup infrastructure; live exploitation activity, severity distribution, and current CVE counts are shown alongside this summary.

FAUCET AI Generated
172
Total CVEs
More Total CVEs than 100% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Acronis International GmbH over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2008
18 years ago
Most Recent CVE
Apr 2, 2026
113 days ago

Self-Reporting Analysis

Of all the CVEs published by Acronis International GmbH as a CNA, 75.5% affect products that Acronis International GmbH develops as a vendor.

75.5%
24.5%
Self-reported: 142 (75.5%)
Third-party: 46 (24.5%)

Of all the CVEs published that affect products developed by Acronis International GmbH, 82.6% are self-published by Acronis International GmbH as a CNA.

82.6%
17.4%
Self-published: 142 (82.6%)
Other CNAs: 30 (17.4%)

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (172 CVEs).

172 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-45249CRITICAL
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructur
Jul 24, 20249.895YESYES
CVE-2022-3405HIGH
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, L
May 3, 20238.841NOYES
CVE-2022-30995HIGH
Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Ba
May 3, 20237.536NOYES
CVE-2025-30412CRITICAL
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acroni
Feb 20, 202610.035NONO
CVE-2025-30411CRITICAL
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acroni
Feb 20, 202610.035NONO
CVE-2020-25736HIGH
Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration.
Jul 15, 20217.835NOYES
CVE-2025-30416CRITICAL
Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis
Feb 20, 202610.034NONO
CVE-2026-28710CRITICAL
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.
Mar 6, 20269.832NONO
CVE-2020-16171MEDIUM
An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom Shard header. The value of this
Sep 21, 20206.529NOYES
CVE-2023-44208CRITICAL
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713,
Oct 4, 20239.128NONO
View all 172 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products172 CVEs
40%
53%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local94 (54.7%)
Network65 (37.8%)
Unknown5 (2.9%)
Physical0 (0.0%)
Adjacent Network8 (4.7%)
Attack Complexity
Low159 (92.4%)
High8 (4.7%)
Unknown5 (2.9%)
User Interaction
None122 (70.9%)
Unknown5 (2.9%)
Required45 (26.2%)
Privileges Required
Low97 (56.4%)
High4 (2.3%)
None66 (38.4%)
Unknown5 (2.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (172 CVEs).

CISA KEV
1 CVE
0.6% of CVEs· 99th percentile
Metasploit
4 CVEs
2.3% of CVEs· 97th percentile
Nuclei
1 CVE
0.6% of CVEs· 95th percentile
ExploitDB
3 CVEs
1.7% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Acronis International GmbH.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Acronis International GmbH — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Acronis International GmbH's Products

View all 3 CNAs →

Top CWEs