CVE-2025-30408: Acronis Cyber Protect 16

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904, Acronis Cyber Protect 16 (Windows) before build 39938.

Affected products

  • Acronis Acronis Cyber Protect 16: before 39938 (fixed in 39938)
  • Acronis Acronis Cyber Protect Cloud Agent: before 39904 (fixed in 39904)

Published 2025-04-24. Last modified 2026-06-17.