Vendor
Acronis vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 13 vulnerabilities in Acronis: 0 in the last 7 days and 1 in the last 90 days, 2 of them critical and 2 exploited in the wild. The most recent, CVE-2026-87886, was published on 17 September 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 2
- Exploited in the wild
- 2
About Acronis
Software company providing backup, disaster recovery, and cyber protection solutions.
Acronis technologies
Latest Acronis vulnerabilities
- CVE-2026-87886: Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin…criticalexploited in the wildCVSS 7.8EPSS 0.2%
- CVE-2026-50033: Acronis DeviceLock DLP local privilege escalation via DLL hijackinghighCVSS 7.3
- CVE-2026-44682: Acronis DeviceLock DLP local privilege escalation via DLL hijackinghighCVSS 7.3
- CVE-2026-44609: Acronis DeviceLock DLP local privilege escalation via EXE hijackinghighCVSS 7.3
- CVE-2026-42061: Acronis DeviceLock DLP local privilege escalation in child processeshighCVSS 7.3
- CVE-2026-41952: Acronis Windows Agents local privilege escalation via improper input validationhighCVSS 7.8EPSS 0.0%
- CVE-2026-41220: Acronis DeviceLock DLP and Cyber Protect Cloud Agent privilege escalationhighCVSS 7.8EPSS 0.0%
- CVE-2026-25852: Acronis DeviceLock DLP privilege escalation via DLL hijackingmediumCVSS 6.7EPSS 0.0%
- CVE-2026-33092: Acronis True Image local privilege escalation via environment variableshighCVSS 7.8EPSS 0.0%
- CVE-2026-33271: Acronis True Image local privilege escalation via insecure folder permissionsmediumCVSS 6.7EPSS 0.1%
- CVE-2026-28728: Acronis True Image DLL hijacking privilege escalationmediumCVSS 6.7EPSS 0.1%
- CVE-2026-27774: Acronis True Image DLL hijacking privilege escalationmediumCVSS 6.7EPSS 0.1%
- CVE-2023-45249: Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerabilitycriticalexploited in the wildCVSS 9.8
Most severe Acronis vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2023-45249: Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2026-87886: Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin…criticalexploited in the wildCVSS 7.8EPSS 0.2%
- CVE-2026-41952: Acronis Windows Agents local privilege escalation via improper input validationhighCVSS 7.8EPSS 0.0%
- CVE-2026-41220: Acronis DeviceLock DLP and Cyber Protect Cloud Agent privilege escalationhighCVSS 7.8EPSS 0.0%
- CVE-2026-33092: Acronis True Image local privilege escalation via environment variableshighCVSS 7.8EPSS 0.0%
- CVE-2026-50033: Acronis DeviceLock DLP local privilege escalation via DLL hijackinghighCVSS 7.3
- CVE-2026-44682: Acronis DeviceLock DLP local privilege escalation via DLL hijackinghighCVSS 7.3
- CVE-2026-44609: Acronis DeviceLock DLP local privilege escalation via EXE hijackinghighCVSS 7.3
- CVE-2026-42061: Acronis DeviceLock DLP local privilege escalation in child processeshighCVSS 7.3
- CVE-2026-28728: Acronis True Image DLL hijacking privilege escalationmediumCVSS 6.7EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 1 | 1 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/acronis.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Acronis vulnerabilities", https://junglewise.ai/threats/vendors/acronis, 26 September 2026.