Known Vulnerabilities for products from Acer
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Acer".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Additional devices specifications by Acer can be found at device.report : Acer
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-50610 json | Not Provided | 2026-09-17 | 2026-09-17 | |
| CVE-2026-50609 json | Not Provided | 2026-09-17 | 2026-09-17 | |
| CVE-2026-50608 json | Not Provided | 2026-09-17 | 2026-09-17 | |
| CVE-2026-50607 json | Not Provided | 2026-09-17 | 2026-09-17 | |
| CVE-2026-50606 json | Not Provided | 2026-09-17 | 2026-09-17 | |
| CVE-2026-50605 json | Not Provided | 2026-09-17 | 2026-09-17 | |
| CVE-2026-50604 json | Not Provided | 2026-09-17 | 2026-09-17 | |
| CVE-2026-50603 json | Not Provided | 2026-09-17 | 2026-09-17 | |
| CVE-2026-50601 json | Not Provided | 2026-08-17 | 2026-08-17 | |
| CVE-2026-50228 json | Not Provided | 2026-09-23 | 2026-09-23 | |
| CVE-2026-50226 json | Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IME... | Not Provided | 2026-06-04 | 2026-07-22 |
| CVE-2026-50225 json | The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to f... | Not Provided | 2026-06-04 | 2026-07-22 |
| CVE-2026-50224 json | The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limi... | Not Provided | 2026-06-04 | 2026-07-22 |
| CVE-2026-50214 json | The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary cr... | Not Provided | 2026-06-04 | 2026-07-22 |
| CVE-2026-50213 json | The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by i... | Not Provided | 2026-06-04 | 2026-07-22 |
| CVE-2026-50212 json | Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endp... | Not Provided | 2026-06-04 | 2026-07-22 |
| CVE-2026-50211 json | Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps... | Not Provided | 2026-06-04 | 2026-07-22 |
| CVE-2026-50210 json | The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay ... | Not Provided | 2026-06-04 | 2026-07-22 |
| CVE-2026-50209 json | Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, sh... | Not Provided | 2026-06-04 | 2026-07-22 |
| CVE-2026-50208 json | High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryp... | Not Provided | 2026-06-04 | 2026-07-22 |
Known software with vulnerabilities from Acer
| Type | Vendor | Product | Version |
|---|---|---|---|
| Hardware | Acer | Ac700 Chromebook | - |
| Application | Acer | Acer Portal | 3.9.3.2006 |
| Application | Acer | Quick Access | - |