CVE-2025-35041: Airship.ai Acropolis
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A remote attacker with valid credentials could brute-force the 6-digit MFA code. Fixed in 10.2.35, 11.0.21, and 11.1.9.
Affected products
- Airship.ai Acropolis: before 10.2.35 (fixed in 10.2.35); from 11.0.0, before 11.0.21 (fixed in 11.0.21); from 11.1.0, before 11.1.9 (fixed in 11.1.9)
Published 2025-09-22. Last modified 2026-06-17.