Cybernews ASUS Issues Urgent Firmware Updates for Critical Router Vulnerabilities
Article Content
- •ASUS patched two critical router vulnerabilities with CVSS scores of 9.4 and 8.9.
- •Users should avoid importing VPN files from untrusted sources to prevent exploitation.
- •Firmware updates are available for affected router models; immediate installation is recommended.
ASUS has released firmware updates to address two critical vulnerabilities in its routers that could allow authenticated attackers to execute arbitrary commands. The most severe flaw, CVE-2026-14157, has a CVSS score of 9.4 and affects routers running firmware version 3.0.0.6_102. Users are advised to only import VPN configuration files from trusted sources to mitigate risks. A second vulnerability, CVE-2026-13313, rated 8.9, also allows command execution with elevated privileges on several firmware versions. ASUS has not confirmed whether these vulnerabilities have been. Additionally, BIOS updates were issued for 13 motherboard models to fix a separate vulnerability. Users are urged to apply these updates immediately to secure their devices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-13313 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What are the CVE identifiers for the vulnerabilities?
How can I protect my ASUS router?
Have these vulnerabilities been exploited in the wild?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…