{"record":"Acronis evidence record","url":"https://nexalign.io/vendors/acronis","vendor":{"slug":"acronis","name":"Acronis","domain":"acronis.com","category":"backup","categoryLabel":"Backup and recovery"},"lastChecked":"2026-07-24T16:17:41.246Z","coverage":{"earliest":"2023-08-31T15:04:10.000Z","latest":"2026-07-24T10:48:15.121Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":102,"kindsOfSource":6,"attributedAdvisories":54,"knownExploited":1,"registerEntriesNotAttributable":1,"practitionerThreads":2,"independentItems":3,"vendorPublishedItems":11,"shareFromSourcesTheVendorDoesNotControl":0.6},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":29,"latest":"2026-06-03T19:26:29.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":25,"latest":"2026-04-30T10:19:14.136Z"},{"source":"Known Exploited Vulnerabilities catalogue","operator":"CISA, United States","classification":"authoritative","items":1,"latest":"2024-07-29T00:00:00.000Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":3,"latest":"2025-08-20T11:00:14.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":3,"latest":"2026-07-17T16:20:42.438Z"},{"source":"The vendor's own documentation","operator":"Vendor website, indexed by nexalign","classification":"vendor-controlled","items":41,"latest":"2026-07-24T10:48:15.121Z"}],"advisories":{"shown":6,"total":54,"truncated":true,"fullList":"https://nexalign.io/vendors/acronis/advisories","items":[{"id":"CVE-2023-45249","description":"Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability","severity":"critical","cvss":null,"knownExploited":true,"date":"2024-07-29T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2023-45249"]},{"id":"CVE-2026-44682","description":"Local privilege escalation due to DLL hijacking vulnerability.","severity":"high","cvss":7.3,"knownExploited":false,"date":"2026-06-03T19:26:29.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34174"]},{"id":"CVE-2026-42061","description":"Local privilege escalation due to excessive permissions assigned to child processes.","severity":"high","cvss":7.3,"knownExploited":false,"date":"2026-06-03T19:26:17.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34173"]},{"id":"CVE-2026-50033","description":"Local privilege escalation due to DLL hijacking vulnerability.","severity":"high","cvss":7.3,"knownExploited":false,"date":"2026-06-03T19:26:05.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34172"]},{"id":"CVE-2026-44609","description":"Local privilege escalation due to EXE hijacking vulnerability.","severity":"high","cvss":7.3,"knownExploited":false,"date":"2026-06-03T19:25:39.000Z","sources":["https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34171"]},{"id":"WID-SEC-2026-1322","description":"Affected products: Acronis Cyber Protect","severity":"high","cvss":9.9,"knownExploited":false,"date":"2026-04-30T10:19:14.136Z","sources":["https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1322"]}]},"practitionerThreads":{"shown":2,"total":2,"truncated":false,"items":[{"title":"Acronis True Image costs performance when not used","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44960718","date":"2025-08-20T11:00:14.000Z"},{"title":"Acronis True Image Costs Performance When Not Used","context":"Hacker News","url":"https://news.ycombinator.com/item?id=44101039","date":"2025-05-26T19:53:30.000Z"}]},"independentCoverage":{"shown":3,"total":3,"truncated":false,"items":[{"title":"Acronis Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/endpoint-protection-platforms/vendor/acronis","date":null},{"title":"Acronis - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Acronis","date":null},{"title":"Private equity house EQT buys majority stake in Acronis","host":"blocksandfiles.com","url":"https://www.blocksandfiles.com/data-protection/2024/08/07/private-equity-house-eqt-buys-majority-stake-in-acronis/1598356","date":null}]},"vendorPublished":{"shown":4,"total":11,"truncated":true,"items":[{"title":"Acronis Cyber Protect Cloud – Řešení kybernetické ochrany pro MSP","url":"https://www.acronis.com/cs/products/cloud/cyber-protect/","date":"2026-07-24T10:48:15.121Z"},{"title":"Řešení kybernetické bezpečnosti a ochrany dat – Acronis","url":"https://www.acronis.com/cs/products/cyber-protect/","date":"2026-07-24T10:48:14.705Z"},{"title":"Vedení společnosti Acronis","url":"https://www.acronis.com/cs/company/leadership/","date":"2026-07-03T04:47:51.419Z"},{"title":"Softwarové řešení pro zálohování a obnovu podniku","url":"https://www.acronis.com/cs/products/cyber-protect/backup/","date":"2026-07-03T04:47:51.237Z"}]},"openQuestions":["A further 1 register entries mention Acronis without naming a product of Acronis as affected. They are excluded rather than counted as vulnerabilities.","Most of what this record contains about capabilities comes from Acronis itself. Treat those statements as claims until an independent source confirms them.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}