Acronis International GmbH is a cybersecurity and data-protection vendor whose vulnerability footprint spans backup, recovery, and endpoint-protection products deployed across enterprise and consumer segments, including flagship offerings such as Cyber Protect, True Image, and Snap Deploy. The vendor's exposure recurs through a characteristic set of weakness classes including uncontrolled search-path elements, missing authorization checks, incorrect default permissions, and cross-site scripting flaws, reflecting the complexity of privileged agent software and web-based management interfaces that operate with elevated system access. Vulnerabilities affecting this vendor lean toward serious outcomes, with a meaningful share reaching critical severity; the weakness classes that recur—particularly those affecting authentication, authorization, and local privilege escalation—align with the high-trust role these products occupy in the backup and recovery chain. Defenders deploying Acronis products should prioritize agent and management-console updates and enforce strict access controls around backup infrastructure; live exploitation activity, severity distribution, and current CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Acronis International GmbH over time
Of all the CVEs published by Acronis International GmbH as a CNA, 75.5% affect products that Acronis International GmbH develops as a vendor.
Of all the CVEs published that affect products developed by Acronis International GmbH, 82.6% are self-published by Acronis International GmbH as a CNA.
Signals from CVEs in this vendor scope (172 CVEs).
172 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45249CRITICAL Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructur | Jul 24, 2024 | 9.8 | 95 | YES | YES |
CVE-2022-3405HIGH Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, L | May 3, 2023 | 8.8 | 41 | NO | YES |
CVE-2022-30995HIGH Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Ba | May 3, 2023 | 7.5 | 36 | NO | YES |
CVE-2025-30412CRITICAL Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acroni | Feb 20, 2026 | 10.0 | 35 | NO | NO |
CVE-2025-30411CRITICAL Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acroni | Feb 20, 2026 | 10.0 | 35 | NO | NO |
CVE-2020-25736HIGH Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration. | Jul 15, 2021 | 7.8 | 35 | NO | YES |
CVE-2025-30416CRITICAL Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis | Feb 20, 2026 | 10.0 | 34 | NO | NO |
CVE-2026-28710CRITICAL Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | Mar 6, 2026 | 9.8 | 32 | NO | NO |
CVE-2020-16171MEDIUM An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom Shard header. The value of this | Sep 21, 2020 | 6.5 | 29 | NO | YES |
CVE-2023-44208CRITICAL Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, | Oct 4, 2023 | 9.1 | 28 | NO | NO |
Signals from CVEs in this vendor scope (172 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Acronis International GmbH.
Media articles that mention a CVE ID that affects a product developed by Acronis International GmbH — matched by CVE ID, not by vendor name.