ASUS released software updates for Control Center Express and Armoury Crate on September 8, 2026. The updates fix several security flaws. The most serious ASUS vulnerability, CVE-2026-19397, could let a nearby attacker take over a host. A separate Armoury Crate flaw can expose a user’s NTLM hash.
- Total: 11 CVEs
- Severity: 1 High · 9 Medium · 1 Low
- Actively exploited: None confirmed
- Highest severity: 7.7 (High · CVSSv4) — CVE-2026-19397
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv4) | Fixed in | Status |
|---|---|---|---|
| CVE-2026-19397 | 7.7 | v1.7.24 | Not exploited |
| CVE-2026-16004 | 5.9 | — | Not exploited |
| CVE-2026-75809 | 5.9 | — | Not exploited |
| CVE-2026-16005 | 5.8 | — | Not exploited |
| CVE-2026-75811 | 5.8 | — | Not exploited |
| CVE-2026-16006 | 5.7 | — | Not exploited |
| CVE-2026-18023 | 5.7 | — | Not exploited |
| CVE-2026-75808 | 5.7 | — | Not exploited |
Why this matters
Both tools run on many ASUS business and gaming systems. So a flaw here reaches a broad user base. The Control Center Express bug is the highest rated, at CVSS 7.7. It hands an attacker control of the target host.
How the attacks work
CVE-2026-19397 is a missing-authentication flaw in the Control Center Express Agent. Per ASUS, it “allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session.” The bug is classed as CWE-306.
The Armoury Crate flaw, CVE-2026-12962, works differently. This ASUS vulnerability abuses a permissive cross-domain policy. A crafted web page sends a UNC-path request to a local service endpoint. That tricks the app into leaking the user’s NTLM hash. The remaining Armoury Crate driver bugs need local access and abuse IOCTL requests.
Affected versions
The Control Center Express flaw affects versions before v1.7.24. The Armoury Crate issues affect earlier builds of that app and its driver. ASUS reports no active exploitation or public proof-of-concept.
Patch and mitigation steps
Update both products now. Move Control Center Express to v1.7.24 or later, then update the client agents. For Armoury Crate, use the built-in Update Center to install the latest version. Review the official ASUS Security Advisory for the full CVE list and steps.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!