CVE-2025-30411
Auth bypass in Acronis Cyber Protect exposes data and allows manipulation.
Is CVE-2025-30411 being exploited?
Not confirmed. CVE-2025-30411 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.69% probability of exploitation in the next 30 days.
How severe is CVE-2025-30411?
CVE-2025-30411 is rated Critical. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2025-30411?
Yes. A fix has been recorded for CVE-2025-30411. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2025-30411 affect?
CVE-2025-30411 affects Acronis Cyber Protect 16 (Linux/Windows) before build 39938, Acronis Cyber Protect 15 (Linux/Windows) before build 41800. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2025-30411?
Patch to fixed builds (CP16 39938+; CP15 41800+).
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Bypass authentication to access and modify sensitive data via affected CP 15/16 installations.
Immediate action required
- affected< 41800
- affected< 39938
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.