Last document update: July 31, 2026
Table of contents
What's new
Backup: Support for HPE StoreOnce Catalyst as a backup destination
Partners with Acronis Cyber Infrastructure can now register HPE StoreOnce Catalyst devices as storage accessed through the Backup Gateway.
Key benefits
- Deduplication hardware support: Use existing HPE StoreOnce Catalyst devices as storage.
- Flexible registration: Register StoreOnce devices with Cyber Protect Cloud during or after adding them to Acronis Cyber Infrastructure.
Supported scenarios
- Add one or more physical HPE StoreOnce devices running generation 5 software as storage.
Licensing
- Solution-based: Backup and DR, Ultimate Protection.
- Service-based (per-workload, per-gigabyte): Standard Protection.
Backup: Run VM backup validation included in the Backup and Disaster Recovery package
Backup validation by running backups as virtual machines was previously included only in the solution-based Ultimate Protection package. It is now included in the solution-based Backup and Disaster Recovery package, at no additional cost.
Key benefits
- Broader access to automated recovery testing: Offer Run VM backup validation without requiring a top-tier package.
- Proven recoverability: Validate backup integrity by booting backups as virtual machines, confirming that a backup can be recovered, not just that it exists.
Supported scenarios
- Run automated or on-demand Run VM validation of virtual machine and physical machine backups under the solution-based Backup and Disaster Recovery package.
Licensing
- Solution-based: Backup and DR, Ultimate Protection.
Security: Expanded coverage and reporting for multi-workload incidents
EDR now recognizes when an attack spans more than two endpoint workloads. It consolidates the related detections into a single incident, instead of creating a separate incident for each workload. As the attack moves from one workload to another, EDR transfers the incident to the new workload. The original incident stays visible as a linked record of where the attack started. Reporting, dashboards, and the incident graph all reflect the full, consolidated incident, including its transfer history. As a result, partners see the complete scope of a multi-workload attack, instead of piecing it together from separate incidents.
Key benefits
- Reduced alert fatigue: EDR consolidates detections across affected workloads into a single, more comprehensive incident, so partners receive one alert for the attack instead of a separate alert for each affected workload.
- Complete and accurate reporting: Dashboard widgets account for transferred incidents, so metrics reflect the full incident rather than only its originating workload.
- Clearer investigation path: A dedicated table links transferred incidents to the active incident, and the incident graph shows threat and process node details.
Supported scenarios
- View incidents that span more than two endpoint workloads.
- See all incidents, including active and transferred ones, from the incident list view.
- Review the table that links transferred incidents to the active incident.
- Preview threat and process node details directly in the incident graph.
- Review dashboard widgets that include transferred incidents: top incident distribution per workload, incident MTTR, security incident burndown, threat status, and incident severity history.
Implementation notes
- Supported platform: Windows endpoints.
- This feature applies to Detection and Response (self-service EDR). Support for Managed Detection and Response (MDR) is planned for a future release.
Licensing
- Solution-based: Security and RMM, Ultimate Protection.
- Service-based (per-workload, per-gigabyte): Detection and Response.
GenAI Protection: Application-level access control
Partners can now configure a GenAI access control policy in a protection plan. This policy controls which generative AI applications a protected organization's workforce can use. It works in one of two modes: allow only specified applications and domains, or block only specified applications and domains while allowing everything else. This helps organizations reduce the risk of data leakage from GenAI applications that fall outside the policy.
Key benefits
- Safe AI adoption: Govern which GenAI applications users can access across the workforce.
- Reduced data leakage risk: Help prevent the use of unsanctioned AI tools that could expose sensitive data.
- Flexible enforcement: Apply AI usage policy based on the allowlist or blocklist without requiring URL filtering.
Supported scenarios
- Control access to web-based, desktop, and SaaS GenAI applications.
- Block or allow applications by name or by associated domain.
- Apply allowlist or blocklist enforcement modes per policy.
Licensing
- Solution-based: Ultimate Protection > Workstations.
- Service-based (per-workload, per-gigabyte): Acronis GenAI Protection > Endpoints.
GenAI Protection: User-level monitoring and reporting
Partners can now identify which user performed a GenAI-related action, not only which device. GenAI Protection widgets and reports include the logged-in account associated with each event. This closes a gap in environments where devices are shared or reassigned between people. Previously, device-only visibility made it hard to attribute a risky or policy-violating action to a specific person. Now, partners and their customers can investigate, enforce policy, and report on GenAI usage by user, in addition to by device.
Key benefits
- Clear accountability: Identify which user performed each GenAI action.
- Faster investigations: Attribute activity to a user without manually correlating device and user records.
- Stronger compliance support: Support user-level auditing and policy enforcement.
Supported scenarios
- Filter and group widgets by user, not only by device.
- Track GenAI activity by user on shared or reassigned devices.
- Review user-level reporting across GenAI usage, attempts to send sensitive data to GenAI applications, and prompt injection events.
Licensing
- Solution-based: Ultimate Protection > Workstations.
- Service-based (per-workload, per-gigabyte): Acronis GenAI Protection > Endpoints.
Integrations: IT Glue documentation integration
Partners can now connect Acronis Cyber Protect Cloud with IT Glue. The integration publishes device, protection, and backup data directly into IT Glue documentation.
Key benefits
- Centralized visibility: View customer, device, and protection data in IT Glue alongside other IT documentation.
- Enriched documentation: The integration enriches IT Glue configurations with Acronis device, protection, and backup and disaster recovery data.
Supported scenarios
- Map IT Glue organizations to existing tenants, or provision new customer tenants directly from the mapping workspace.
- Match devices automatically by hostname, serial number, or MAC address, and optionally create new IT Glue configurations for unmatched devices.
- Publish backup, protection, and access data as structured flexible assets attached to each device configuration.
Licensing
- Available to all Acronis Cyber Protect Cloud partners at no additional cost.
Service Desk (Early Access)
Partners can now join the Early Access Program for Service Desk, which automates ticket creation from alerts and applies AI assistance to summarize and resolve tickets.
Key benefits
- Reduced alert noise: Automate alert-to-ticket conversion by using playbooks.
- Faster resolution: AI assistance triages each ticket, summarizes the issue, and identifies a likely root cause. This reduces the time technicians spend investigating before they resolve it.
- Lower service delivery costs: Automate ticket handling, including autonomous resolution of eligible tickets.
Supported scenarios
- Convert alerts to tickets automatically by using playbooks.
- Generate AI ticket summaries.
- Get AI-assisted ticket resolution.
- Automatically close routine tickets that AI can resolve with high confidence, without technician involvement.
Implementation notes
- Available through the Early Access Program.
Licensing
- N/A, part of Acronis Cyber Platform.
Disaster Recovery: Support for Ubuntu 24.x workloads
Partners can now perform disaster recovery failover for Ubuntu 24.x physical and virtual servers.
Key benefits
- Broader OS coverage: Protect the latest Ubuntu workloads with Disaster Recovery.
Supported scenarios
- Perform disaster recovery failover for Ubuntu 24.04 LTS and 24.10 physical and virtual servers.
Licensing
- Solution-based: Backup and DR, Ultimate Protection.
Updated Components
Acronis Cyber Protection agent
The Acronis Cyber Protection agent has the following new versions.
- Acronis Cyber Protection agent for Windows (v.26.7.42848)
- Acronis Cyber Protection agent for Mac (v.26.7.42848)
- Acronis Cyber Protection agent for Linux (v.26.7.42848)
For more information about the release history of the Acronis Cyber Protection agent, see the agent release notes.
Fixed issues
Security
For information about security issues fixed in this release, see https://security-advisory.acronis.com/updates/UPD-2607-7a81-1d91.
Acronis Cyber Protect Cloud
Backup
- [PLTFRM-92153] After a virtual appliance was removed, the "Updating the Virtual Appliance" activity could remain in progress indefinitely instead of expiring. This issue is now resolved.
- [PLTFRM-86413] S3-compatible storage vaults, such as Wasabi, were not listed when configuring recovery by using bootable media. This issue is now resolved.
- [ABR-407001] When a virtual appliance update failed due to insufficient free space, the update did not revert successfully, which could cause the virtual appliance to enter a boot loop. This issue is now resolved.
- [ABR-400847] Recovery of Microsoft 365 SharePoint sites from cloud-to-cloud backups failed with the error "archive is corrupted." This issue is now resolved.
- [ABR-379573] A file backup could be empty when the inclusion filter used the same path as the items selected for backup. This issue is now resolved.
- [ARC-1075] Backup, replication, or retention activities running against large backup archives could stop making progress and eventually fail with the error "The running backup has not shown any progress for some time and may be frozen." This issue is now resolved.
- [PLTFRM-92717] A "No successful backups have been performed for more than X days" alert could be generated shortly after a backup completed successfully, for weekly, monthly, weekend, or advanced availability group-excluded protection plans. This issue is now resolved.
Cyber Protection agent
- [KERNEL-21152] Agent installation failed on Rocky Linux 9.8 or AlmaLinux 9.8 with the error "Failed to install the file_protector kernel module." This issue is now resolved.
- [ABR-432437] On Mac, the protection agent continuously created empty scheduler tasks, which caused high CPU usage and the accumulation of a large number of task files. This issue is now resolved.
GenAI Protection
- [DEVLOCK-7197] In Japanese-language environments, GenAI Protection DLP did not block personal identifiable information, such as names and addresses, because the address-detection rule did not trigger on standard Japanese addresses. This issue is now resolved.
Known issues and limitations
Acronis Cyber Protect Cloud
Backup
- [ABR-365442] The backup validation completes successfully, but the validation status is incorrect or missing in backup sets with a large number of backups.
- [ABR-361097] It is possible to create backups with special characters in their names, but such backups are not accessible when saved on a network storage.
- Solution: Do not use special characters in backup names, even though the application allows you to.
- [ABR-305920] The backups of System state performed via the Windows Server Backup feature fail with the error message "The process cannot access the file because it is being used by another process."
Bootable media
- [ABR-358235] WinPE-based media: Unable to browse backup files if the cloud storage location contains corrupted backup archives.
Cyber Protection agent
Note: Starting with the 26.09 release, the Cyber Protection agent for Mac will no longer support macOS 12 and earlier versions. The minimum supported macOS version will become macOS 13.
Disaster recovery
- If the tenant (customer or partner) is disabled or deleted while an Automated Failover is in progress, the operation fails with the error "Please try again later or contact Support" while it should indicate that the tenant is no longer accessible.
Virtualization protection
- [ABR-383978] No alert about almost reached storage quota is displayed for agentless Microsoft Azure virtual machine backups.
- [ABR-383972] No alert about exceeded storage quota is displayed for agentless Microsoft Azure virtual machine backups.
For more information on known issues and workarounds, please visit our Knowledge Base.