ThreatCluster

Critical Vulnerability in ASUS Control Center Exposes Systems to Remote Attacks

First seen 7 Sep 2026, 06:13 UTC CybersecuritynewsGbhackers 72

Article Content

Browse articles
ThreatCluster

ASUS has released an urgent security update for ASUS Control Center Enterprise (ACC) due to a critical vulnerability, tracked as CVE-2026-75754, that allows remote attackers to gain full administrative control without authentication. The flaw affects ACC version 4.0.0.2 and earlier, enabling unauthenticated root access. The vulnerability was first published on September 4, 2026, and has a CVSS score of 10.0, indicating maximum severity. Researchers have confirmed that the flaw allows attackers to control all devices managed by the ACC platform. Users are strongly advised to update to the latest version to mitigate the risk. The advisory emphasizes the urgent need for immediate action to protect affected systems.

Key Points: • CVE-2026-75754 allows unauthenticated root access to ACC systems. • ASUS Control Center versions 4.0.0.2 and earlier are affected. • Immediate patching is required due to the critical nature of this vulnerability.

Ask AI about this cluster

Timeline

2026-09-04
CVE-2026-75754 published
ASUS disclosed a critical vulnerability in ACC that allows unauthenticated root access.
Gbhackers
2026-09-06
ASUS issues security update
ASUS released an urgent update for ACC to address the critical vulnerability CVE-2026-75754.
Cybersecuritynews