True Image
Vendor:
First CVE: Mar 10, 2008 · Active for 18 years
25
Total CVEs
More Total CVEs than 95% of tracked products
4.2
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact True Image over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2008
18 years ago
Most Recent CVE
Apr 2, 2026
114 days ago
CVE Severity & Scoring
True Image25 CVEs
24%
76%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local21 (84.0%)
Network1 (4.0%)
Unknown2 (8.0%)
Physical0 (0.0%)
Adjacent Network1 (4.0%)
Attack Complexity
Low19 (76.0%)
High4 (16.0%)
Unknown2 (8.0%)
User Interaction
None14 (56.0%)
Unknown2 (8.0%)
Required9 (36.0%)
Privileges Required
Low18 (72.0%)
High1 (4.0%)
None4 (16.0%)
Unknown2 (8.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25736HIGH Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration. | Jul 15, 2021 | 7.8 | 35 | NO | YES |
CVE-2022-24115HIGH Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (macOS) before build 39605, Acr | Feb 4, 2022 | 7.8 | 24 | NO | NO |
CVE-2022-24113HIGH Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acr | Feb 4, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-44204HIGH Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis | Feb 4, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-32581HIGH Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent prior to build 26653, Acronis Cyber Protect prior to build 2 | Aug 5, 2021 | 8.1 | 24 | NO | NO |
CVE-2021-32580HIGH Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking. | Aug 5, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-32577HIGH Acronis True Image prior to 2021 Update 5 for Windows allowed local privilege escalation due to insecure folder permissions. | Aug 5, 2021 | 7.8 | 24 | NO | NO |
CVE-2026-33271MEDIUM Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 42902. | Apr 2, 2026 | 6.7 | 23 | NO | NO |
CVE-2026-28728MEDIUM Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902. | Apr 2, 2026 | 6.7 | 23 | NO | NO |
CVE-2026-27774MEDIUM Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902. | Apr 2, 2026 | 6.7 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.0% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For True Image
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2021 | 16 | 7.7 | 0.3% | 0 | 1 |
| 2020 | 2 | 7.8 | 1.2% | 0 | 1 |
| 2019 | 2 | 7.8 | 1.2% | 0 | 1 |