Vendor
Acer vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 49 vulnerabilities in Acer: 2 in the last 7 days and 12 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-50228, was published on 23 September 2026. 4 technologies have a page of their own.
- Last 7 days
- 2
- Last 90 days
- 12
- Critical, all time
- 0
- Exploited in the wild
- 0
About Acer
A multinational technology corporation specializing in advanced electronics and computer hardware.
Acer technologies
Latest Acer vulnerabilities
- CVE-2026-50228: Acer NitroSense arbitrary code execution via exposed DevToolsinfoEPSS 0.1%
- CVE-2026-50227: Acer NitroSense MQTT broker authentication bypassinfoEPSS 0.4%
- CVE-2026-50610: Acer NitroSense privilege escalation via System MonitoringinfoEPSS 0.1%
- CVE-2026-50609: Acer System Monitoring insufficient access control in Named Pipe serviceinfoEPSS 0.1%
- CVE-2026-50608: Acer NitroSense authentication bypass in WebSocket handshakeinfoEPSS 0.2%
- CVE-2026-50607: Acer NitroSense WebSocket service exposure on all network interfacesinfoEPSS 0.4%
- CVE-2026-50606: Acer NitroSense and PredatorSense hard-coded encryption keyinfoEPSS 0.1%
- CVE-2026-50605: Acer Agent Service insufficient access control in registry operationsinfoEPSS 0.1%
- CVE-2026-50604: Acer Agent Service authentication bypass in socket handshakeinfoEPSS 0.2%
- CVE-2026-50603: Acer NitroSense and PredatorSense hardcoded encryption keyinfoEPSS 0.1%
- CVE-2026-50602: Acer Planet9 privilege escalation via incorrect file permissionsinfoEPSS 0.1%
- CVE-2026-50601: Acer Planet9 hardcoded API key exposureinfoEPSS 0.4%
- CVE-2026-50226: Acer Connect M6E hard-coded AES keys in OTA applicationinfoCVSS 6.9
- CVE-2026-50225: Acer Connect M6E missing bot mitigation in registration endpointinfoCVSS 8.8
- CVE-2026-50224: Acer Connect M6E 5G Router Information Exposure in Web Admin PanelinfoCVSS 6.9
- CVE-2026-50214: Acer Connect M6E shared global API token in /v1/Plan serviceinfoCVSS 9.3
- CVE-2026-50213: Acer Connect M6E IDOR in account validation endpointinfoCVSS 8.7
- CVE-2026-50212: Acer Connect M6E 5G Router denial of service in dissociation APIinfoCVSS 7.1
- CVE-2026-50211: Acer Connect M6E exposed engineering diagnostics in firmwareinfoCVSS 8.8
- CVE-2026-50210: Acer Connect M6E 5G Router weak encryption via static IVsinfoCVSS 6.9
- CVE-2026-50209: Acer Connect M6E MDM hijacking via Broadcast Receiver privilege escalationinfoCVSS 9.3
- CVE-2026-50208: Acer Connect M6E TLS validation bypass and hard-coded keysinfoCVSS 9.2
- CVE-2026-50207: Acer Connect M6E unverified AT commands in Binder boundaryinfoCVSS 8.5
- CVE-2026-50206: Acer Connect M6E command injection in VPN profile settingsinfoCVSS 8.5
- CVE-2026-50205: Acer Connect M6E sensitive information disclosure in system logsinfoCVSS 8.8
Most severe Acer vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-8069: Acer PredatorSense privilege escalation in Windows Named PipehighCVSS 7.8EPSS 0.2%
- CVE-2026-49185: Acer Connect M6E Command Injection in FieldX MDMinfoCVSS 10
- CVE-2026-49201: Acer Wave 7 Router hardcoded AES key in upload.cgiinfoCVSS 10
- CVE-2026-49200: Acer Wave 7 Router information disclosure in acer_cgi.loginfoCVSS 10
- CVE-2026-49199: Acer Connect W6x command injection in MQTT brokerinfoCVSS 10
- CVE-2026-49197: Acer Connect W6x Router authentication bypass in app endpointsinfoCVSS 10
- CVE-2026-49194: Acer Connect M6E authentication bypass via SCREEN_CLICK debugging routineinfoCVSS 9.4
- CVE-2026-49190: Acer Connect M6E missing authorization for internal opcodesinfoCVSS 9.4
- CVE-2026-50214: Acer Connect M6E shared global API token in /v1/Plan serviceinfoCVSS 9.3
- CVE-2026-50209: Acer Connect M6E MDM hijacking via Broadcast Receiver privilege escalationinfoCVSS 9.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 2 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 8 | 0 | |
| 21 Sep 2026 | 2 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/acer.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Acer vulnerabilities", https://junglewise.ai/threats/vendors/acer, 26 September 2026.