CVE-2026-28713: High severity Acronis Cyber Protect Cloud Agent vulnerability
Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud Agent (VMware) before build 36943, Acronis Cyber Protect 17 (VMware) before build 41186.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28713?
CVE-2026-28713 is a high severity vulnerability due to the presence of default credentials in Acronis software.
How do I fix CVE-2026-28713?
To fix CVE-2026-28713, update Acronis Cyber Protect Cloud Agent to build 36943 or later and Acronis Cyber Protect 17 to build 41186 or later.
Which products are affected by CVE-2026-28713?
CVE-2026-28713 affects Acronis Cyber Protect Cloud Agent (VMware) before build 36943 and Acronis Cyber Protect 17 (VMware) before build 41186.
What risks are associated with CVE-2026-28713?
The risks associated with CVE-2026-28713 include unauthorized access and potential compromise of the virtual appliance due to default credentials.
Is there a workaround for CVE-2026-28713 before patching?
There are no documented workarounds for CVE-2026-28713; patching to the latest version is the recommended approach.