{"schema_version":1,"title":"Acer vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 49 vulnerabilities in Acer: 2 in the last 7 days and 12 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-50228, was published on 23 September 2026. 4 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/acer","json_url":"https://junglewise.ai/threats/vendors/acer.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/acer","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":1,"all_time":49,"critical":0,"exploited":0,"last_7_days":2,"last_30_days":10,"last_90_days":12,"last_365_days":49},"latest":[{"cve":"CVE-2026-50228","epss":0.0013,"slug":"cve-2026-50228-an-unauthenticated-local-attacker-can-connect-to-the-electron","title":"Acer NitroSense arbitrary code execution via exposed DevTools","severity":"info","exploited":false,"published_at":"2026-09-23T08:17:10.493+00:00","url":"https://junglewise.ai/threats/cve-2026-50228-an-unauthenticated-local-attacker-can-connect-to-the-electron"},{"cve":"CVE-2026-50227","epss":0.0035,"slug":"cve-2026-50227-an-unauthenticated-local-attacker-can-connect-to-the-mqtt-broker","title":"Acer NitroSense MQTT broker authentication bypass","severity":"info","exploited":false,"published_at":"2026-09-23T08:17:09.383+00:00","url":"https://junglewise.ai/threats/cve-2026-50227-an-unauthenticated-local-attacker-can-connect-to-the-mqtt-broker"},{"cve":"CVE-2026-50610","epss":0.0013,"slug":"cve-2026-50610-acer-nitrosense-privilege-escalation-via-system-monitoring","title":"Acer NitroSense privilege escalation via System Monitoring","severity":"info","exploited":false,"published_at":"2026-09-17T09:16:41.487+00:00","url":"https://junglewise.ai/threats/cve-2026-50610-acer-nitrosense-privilege-escalation-via-system-monitoring"},{"cve":"CVE-2026-50609","epss":0.0013,"slug":"cve-2026-50609-acer-system-monitoring-insufficient-access-control-in-named-pipe","title":"Acer System Monitoring insufficient access control in Named Pipe service","severity":"info","exploited":false,"published_at":"2026-09-17T09:16:41.37+00:00","url":"https://junglewise.ai/threats/cve-2026-50609-acer-system-monitoring-insufficient-access-control-in-named-pipe"},{"cve":"CVE-2026-50608","epss":0.0021,"slug":"cve-2026-50608-acer-nitrosense-authentication-bypass-in-websocket-handshake","title":"Acer NitroSense authentication bypass in WebSocket handshake","severity":"info","exploited":false,"published_at":"2026-09-17T09:16:41.253+00:00","url":"https://junglewise.ai/threats/cve-2026-50608-acer-nitrosense-authentication-bypass-in-websocket-handshake"},{"cve":"CVE-2026-50607","epss":0.0043,"slug":"cve-2026-50607-acer-nitrosense-websocket-service-exposure-on-all-network","title":"Acer NitroSense WebSocket service exposure on all network interfaces","severity":"info","exploited":false,"published_at":"2026-09-17T08:17:01.32+00:00","url":"https://junglewise.ai/threats/cve-2026-50607-acer-nitrosense-websocket-service-exposure-on-all-network"},{"cve":"CVE-2026-50606","epss":0.001,"slug":"cve-2026-50606-acer-nitrosense-and-predatorsense-hard-coded-encryption-key","title":"Acer NitroSense and PredatorSense hard-coded encryption key","severity":"info","exploited":false,"published_at":"2026-09-17T08:17:01.177+00:00","url":"https://junglewise.ai/threats/cve-2026-50606-acer-nitrosense-and-predatorsense-hard-coded-encryption-key"},{"cve":"CVE-2026-50605","epss":0.0013,"slug":"cve-2026-50605-acer-agent-service-insufficient-access-control-in-registry","title":"Acer Agent Service insufficient access control in registry operations","severity":"info","exploited":false,"published_at":"2026-09-17T08:17:01.01+00:00","url":"https://junglewise.ai/threats/cve-2026-50605-acer-agent-service-insufficient-access-control-in-registry"},{"cve":"CVE-2026-50604","epss":0.0021,"slug":"cve-2026-50604-acer-agent-service-authentication-bypass-in-socket-handshake","title":"Acer Agent Service authentication bypass in socket handshake","severity":"info","exploited":false,"published_at":"2026-09-17T05:17:01.943+00:00","url":"https://junglewise.ai/threats/cve-2026-50604-acer-agent-service-authentication-bypass-in-socket-handshake"},{"cve":"CVE-2026-50603","epss":0.001,"slug":"cve-2026-50603-acer-nitrosense-and-predatorsense-hardcoded-encryption-key","title":"Acer NitroSense and PredatorSense hardcoded encryption key","severity":"info","exploited":false,"published_at":"2026-09-17T04:17:46.93+00:00","url":"https://junglewise.ai/threats/cve-2026-50603-acer-nitrosense-and-predatorsense-hardcoded-encryption-key"},{"cve":"CVE-2026-50602","epss":0.0014,"slug":"cve-2026-50602-acer-planet9-privilege-escalation-via-incorrect-file-permissions","title":"Acer Planet9 privilege escalation via incorrect file permissions","severity":"info","exploited":false,"published_at":"2026-08-17T03:16:50.84+00:00","url":"https://junglewise.ai/threats/cve-2026-50602-acer-planet9-privilege-escalation-via-incorrect-file-permissions"},{"cve":"CVE-2026-50601","epss":0.0041,"slug":"cve-2026-50601-acer-planet9-hardcoded-api-key-exposure","title":"Acer Planet9 hardcoded API key exposure","severity":"info","exploited":false,"published_at":"2026-08-17T03:16:50.703+00:00","url":"https://junglewise.ai/threats/cve-2026-50601-acer-planet9-hardcoded-api-key-exposure"},{"cve":"CVE-2026-50226","cvss":6.9,"slug":"cve-2026-50226-acer-connect-m6e-hard-coded-aes-keys-in-ota-application","title":"Acer Connect M6E hard-coded AES keys in OTA application","severity":"info","exploited":false,"published_at":"2026-06-04T10:16:40.247+00:00","url":"https://junglewise.ai/threats/cve-2026-50226-acer-connect-m6e-hard-coded-aes-keys-in-ota-application"},{"cve":"CVE-2026-50225","cvss":8.8,"slug":"cve-2026-50225-acer-connect-m6e-missing-bot-mitigation-in-registration-endpoint","title":"Acer Connect M6E missing bot mitigation in registration endpoint","severity":"info","exploited":false,"published_at":"2026-06-04T10:16:40.123+00:00","url":"https://junglewise.ai/threats/cve-2026-50225-acer-connect-m6e-missing-bot-mitigation-in-registration-endpoint"},{"cve":"CVE-2026-50224","cvss":6.9,"slug":"cve-2026-50224-acer-connect-m6e-5g-router-information-exposure-in-web-admin","title":"Acer Connect M6E 5G Router Information Exposure in Web Admin Panel","severity":"info","exploited":false,"published_at":"2026-06-04T10:16:40.003+00:00","url":"https://junglewise.ai/threats/cve-2026-50224-acer-connect-m6e-5g-router-information-exposure-in-web-admin"},{"cve":"CVE-2026-50214","cvss":9.3,"slug":"cve-2026-50214-acer-connect-m6e-shared-global-api-token-in-v1-plan-service","title":"Acer Connect M6E shared global API token in /v1/Plan service","severity":"info","exploited":false,"published_at":"2026-06-04T10:16:39.85+00:00","url":"https://junglewise.ai/threats/cve-2026-50214-acer-connect-m6e-shared-global-api-token-in-v1-plan-service"},{"cve":"CVE-2026-50213","cvss":8.7,"slug":"cve-2026-50213-acer-connect-m6e-idor-in-account-validation-endpoint","title":"Acer Connect M6E IDOR in account validation endpoint","severity":"info","exploited":false,"published_at":"2026-06-04T09:16:29.987+00:00","url":"https://junglewise.ai/threats/cve-2026-50213-acer-connect-m6e-idor-in-account-validation-endpoint"},{"cve":"CVE-2026-50212","cvss":7.1,"slug":"cve-2026-50212-acer-connect-m6e-5g-router-denial-of-service-in-dissociation-api","title":"Acer Connect M6E 5G Router denial of service in dissociation API","severity":"info","exploited":false,"published_at":"2026-06-04T09:16:29.847+00:00","url":"https://junglewise.ai/threats/cve-2026-50212-acer-connect-m6e-5g-router-denial-of-service-in-dissociation-api"},{"cve":"CVE-2026-50211","cvss":8.8,"slug":"cve-2026-50211-acer-connect-m6e-exposed-engineering-diagnostics-in-firmware","title":"Acer Connect M6E exposed engineering diagnostics in firmware","severity":"info","exploited":false,"published_at":"2026-06-04T09:16:29.7+00:00","url":"https://junglewise.ai/threats/cve-2026-50211-acer-connect-m6e-exposed-engineering-diagnostics-in-firmware"},{"cve":"CVE-2026-50210","cvss":6.9,"slug":"cve-2026-50210-acer-connect-m6e-5g-router-weak-encryption-via-static-ivs","title":"Acer Connect M6E 5G Router weak encryption via static IVs","severity":"info","exploited":false,"published_at":"2026-06-04T09:16:29.563+00:00","url":"https://junglewise.ai/threats/cve-2026-50210-acer-connect-m6e-5g-router-weak-encryption-via-static-ivs"},{"cve":"CVE-2026-50209","cvss":9.3,"slug":"cve-2026-50209-acer-connect-m6e-mdm-hijacking-via-broadcast-receiver-privilege","title":"Acer Connect M6E MDM hijacking via Broadcast Receiver privilege escalation","severity":"info","exploited":false,"published_at":"2026-06-04T09:16:29.423+00:00","url":"https://junglewise.ai/threats/cve-2026-50209-acer-connect-m6e-mdm-hijacking-via-broadcast-receiver-privilege"},{"cve":"CVE-2026-50208","cvss":9.2,"slug":"cve-2026-50208-acer-connect-m6e-tls-validation-bypass-and-hard-coded-keys","title":"Acer Connect M6E TLS validation bypass and hard-coded keys","severity":"info","exploited":false,"published_at":"2026-06-04T09:16:29.277+00:00","url":"https://junglewise.ai/threats/cve-2026-50208-acer-connect-m6e-tls-validation-bypass-and-hard-coded-keys"},{"cve":"CVE-2026-50207","cvss":8.5,"slug":"cve-2026-50207-acer-connect-m6e-unverified-at-commands-in-binder-boundary","title":"Acer Connect M6E unverified AT commands in Binder boundary","severity":"info","exploited":false,"published_at":"2026-06-04T09:16:29.137+00:00","url":"https://junglewise.ai/threats/cve-2026-50207-acer-connect-m6e-unverified-at-commands-in-binder-boundary"},{"cve":"CVE-2026-50206","cvss":8.5,"slug":"cve-2026-50206-acer-connect-m6e-command-injection-in-vpn-profile-settings","title":"Acer Connect M6E command injection in VPN profile settings","severity":"info","exploited":false,"published_at":"2026-06-04T07:16:28.177+00:00","url":"https://junglewise.ai/threats/cve-2026-50206-acer-connect-m6e-command-injection-in-vpn-profile-settings"},{"cve":"CVE-2026-50205","cvss":8.8,"slug":"cve-2026-50205-acer-connect-m6e-sensitive-information-disclosure-in-system-logs","title":"Acer Connect M6E sensitive information disclosure in system logs","severity":"info","exploited":false,"published_at":"2026-06-04T07:16:28.023+00:00","url":"https://junglewise.ai/threats/cve-2026-50205-acer-connect-m6e-sensitive-information-disclosure-in-system-logs"}],"vendor":{"hub":true,"name":"Acer","slug":"acer","homepage":"https://www.acer.com/","description":"A multinational technology corporation specializing in advanced electronics and computer hardware.","url":"https://junglewise.ai/threats/vendors/acer"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":2}],"most_severe":[{"cve":"CVE-2026-8069","cvss":7.8,"epss":0.0017,"slug":"cve-2026-8069-acer-predatorsense-privilege-escalation-in-windows-named-pipe","title":"Acer PredatorSense privilege escalation in Windows Named Pipe","severity":"high","exploited":false,"published_at":"2026-05-08T07:16:29.443+00:00","url":"https://junglewise.ai/threats/cve-2026-8069-acer-predatorsense-privilege-escalation-in-windows-named-pipe"},{"cve":"CVE-2026-49185","cvss":10,"slug":"cve-2026-49185-acer-connect-m6e-command-injection-in-fieldx-mdm","title":"Acer Connect M6E Command Injection in FieldX MDM","severity":"info","exploited":false,"published_at":"2026-06-04T04:17:15.387+00:00","url":"https://junglewise.ai/threats/cve-2026-49185-acer-connect-m6e-command-injection-in-fieldx-mdm"},{"cve":"CVE-2026-49201","cvss":10,"slug":"cve-2026-49201-acer-wave-7-router-hardcoded-aes-key-in-upload-cgi","title":"Acer Wave 7 Router hardcoded AES key in upload.cgi","severity":"info","exploited":false,"published_at":"2026-05-29T11:16:17.183+00:00","url":"https://junglewise.ai/threats/cve-2026-49201-acer-wave-7-router-hardcoded-aes-key-in-upload-cgi"},{"cve":"CVE-2026-49200","cvss":10,"slug":"cve-2026-49200-acer-wave-7-router-information-disclosure-in-acer-cgi-log","title":"Acer Wave 7 Router information disclosure in acer_cgi.log","severity":"info","exploited":false,"published_at":"2026-05-29T09:16:18.27+00:00","url":"https://junglewise.ai/threats/cve-2026-49200-acer-wave-7-router-information-disclosure-in-acer-cgi-log"},{"cve":"CVE-2026-49199","cvss":10,"slug":"cve-2026-49199-acer-connect-w6x-command-injection-in-mqtt-broker","title":"Acer Connect W6x command injection in MQTT broker","severity":"info","exploited":false,"published_at":"2026-05-29T09:16:18.143+00:00","url":"https://junglewise.ai/threats/cve-2026-49199-acer-connect-w6x-command-injection-in-mqtt-broker"},{"cve":"CVE-2026-49197","cvss":10,"slug":"cve-2026-49197-acer-connect-w6x-router-authentication-bypass-in-app-endpoints","title":"Acer Connect W6x Router authentication bypass in app endpoints","severity":"info","exploited":false,"published_at":"2026-05-29T09:16:17.877+00:00","url":"https://junglewise.ai/threats/cve-2026-49197-acer-connect-w6x-router-authentication-bypass-in-app-endpoints"},{"cve":"CVE-2026-49194","cvss":9.4,"slug":"cve-2026-49194-acer-connect-m6e-authentication-bypass-via-screen-click-debugging","title":"Acer Connect M6E authentication bypass via SCREEN_CLICK debugging routine","severity":"info","exploited":false,"published_at":"2026-06-04T07:16:27.437+00:00","url":"https://junglewise.ai/threats/cve-2026-49194-acer-connect-m6e-authentication-bypass-via-screen-click-debugging"},{"cve":"CVE-2026-49190","cvss":9.4,"slug":"cve-2026-49190-acer-connect-m6e-missing-authorization-for-internal-opcodes","title":"Acer Connect M6E missing authorization for internal opcodes","severity":"info","exploited":false,"published_at":"2026-06-04T07:16:26.86+00:00","url":"https://junglewise.ai/threats/cve-2026-49190-acer-connect-m6e-missing-authorization-for-internal-opcodes"},{"cve":"CVE-2026-50214","cvss":9.3,"slug":"cve-2026-50214-acer-connect-m6e-shared-global-api-token-in-v1-plan-service","title":"Acer Connect M6E shared global API token in /v1/Plan service","severity":"info","exploited":false,"published_at":"2026-06-04T10:16:39.85+00:00","url":"https://junglewise.ai/threats/cve-2026-50214-acer-connect-m6e-shared-global-api-token-in-v1-plan-service"},{"cve":"CVE-2026-50209","cvss":9.3,"slug":"cve-2026-50209-acer-connect-m6e-mdm-hijacking-via-broadcast-receiver-privilege","title":"Acer Connect M6E MDM hijacking via Broadcast Receiver privilege escalation","severity":"info","exploited":false,"published_at":"2026-06-04T09:16:29.423+00:00","url":"https://junglewise.ai/threats/cve-2026-50209-acer-connect-m6e-mdm-hijacking-via-broadcast-receiver-privilege"}],"generated_at":"2026-09-27T03:07:00.185062+00:00","technologies":[{"name":"Acer Connect M6E 5G Portable WiFi Router","slug":"connect-m6e-5g-portable-wifi-router","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/connect-m6e-5g-portable-wifi-router"},{"name":"Acer NitroSense","slug":"nitrosense","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/nitrosense"},{"name":"Acer Predatorsense","slug":"predatorsense","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/predatorsense"},{"name":"Acer Connect W6x Router","slug":"connect-w6x-router","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/connect-w6x-router"}]}