CVE-2026-28728: Medium severity Acronis Acronis True Image (Windows) vulnerability
Published Apr 2, 2026
·Updated
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (Windows) before build 42902.
Affected Software
2 affected components
Acronis Acronis True Image (Windows)<42902
Acronis True Image Windows<2026
Event History
Apr 2, 2026
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-28728?
CVE-2026-28728 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2026-28728?
To fix CVE-2026-28728, update Acronis True Image (Windows) to build 42902 or later.
3
What products are affected by CVE-2026-28728?
Acronis True Image (Windows) before build 42902 is affected by CVE-2026-28728.
4
What type of attack can be executed through CVE-2026-28728?
CVE-2026-28728 allows for local privilege escalation via DLL hijacking.
5
Is CVE-2026-28728 a remote or local attack vulnerability?
CVE-2026-28728 is a local attack vulnerability, requiring local access to the system.