Vendor
ASUS vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 37 vulnerabilities in ASUS: 0 in the last 7 days and 27 in the last 90 days, 3 of them critical and 3 exploited in the wild. The most recent, CVE-2026-75811, was published on 8 September 2026. 5 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 27
- Critical, all time
- 3
- Exploited in the wild
- 3
About ASUS
A multinational computer hardware and consumer electronics company.
ASUS technologies
Latest ASUS vulnerabilities
- CVE-2026-75811: ASUS Armoury Crate privilege escalation via driver authentication bypassinfoEPSS 0.1%
- CVE-2026-75810: ASUS Armoury Crate exposed dangerous method denial of serviceinfoEPSS 0.1%
- CVE-2026-75809: ASUS Armoury Crate privilege escalation via insufficient IOCTL access controlinfoEPSS 0.1%
- CVE-2026-75808: ASUS Armoury Crate resource exhaustion in memory allocationinfoEPSS 0.1%
- CVE-2026-19397: ASUS Control Center Express Agent missing authentication in critical functioninfoEPSS 0.2%
- CVE-2026-18023: ASUS Armoury Crate driver sensitive information disclosureinfoEPSS 0.1%
- CVE-2026-16006: ASUS Armoury Crate kernel virtual address disclosure via IOCTLinfoEPSS 0.1%
- CVE-2026-16005: ASUS Armoury Crate driver use-after-free via IOCTLinfoCVSS 6.5EPSS 0.1%
- CVE-2026-16004: ASUS Armoury Crate driver insufficient access control in IOCTLinfoEPSS 0.1%
- CVE-2026-16003: ASUS Armoury Crate driver privilege escalation via IOCTL access control bypassinfoEPSS 0.1%
- CVE-2026-12962: ASUS Armoury Crate cross-domain policy NTLM hash theftinfoEPSS 0.4%
- CVE-2026-75754: ASUS Control Center missing authentication and hard-coded credentialsinfoCVSS 9.8EPSS 0.3%
- CVE-2026-19398: ASUS FA507NU and FA507NV BIOS out-of-bounds write in SmiFlash SMMinfoEPSS 0.1%
- CVE-2026-8917: ASUS GPU Tweak untrusted pointer dereference IOCTL privilege escalationinfoEPSS 0.1%
- CVE-2026-16727: ASUS Armoury Crate race condition privilege escalationinfoCVSS 7.3
- CVE-2019-25764: ASUS AURA SYNC privilege escalation in driver IOCTLinfoCVSS 7.3
- CVE-2026-8920: ASUS Aura Wallpaper Service path traversal and communication bypassinfoCVSS 8.5
- CVE-2026-8919: ASUS GameSDK permissive cross-domain policy in local service endpointinfoCVSS 7.2
- CVE-2026-15030: ASUS System Control Interface out-of-bounds read via IOCTLinfoCVSS 5.6
- CVE-2026-15029: ASUS System Control Interface Untrusted Pointer DereferenceinfoCVSS 8.4
- CVE-2026-13585: ASUS System Control Interface and Business Manager Information Disclosure and DoSinfoCVSS 8.2
- CVE-2026-13385: ASUS Router remote command execution via improper certificate validationinfoCVSS 9.5
- CVE-2026-11851: ASUS Router SQL injection in web management interfaceinfoCVSS 5.9
- CVE-2026-8921: ASUS Business Manager privilege escalation via tampered IPC messageinfoCVSS 8.5
- CVE-2026-12960: ASUS Router App improper export of Android componentsinfoCVSS 6
Most severe ASUS vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2021-32030: ASUS Routers authentication bypass in administrator interfacecriticalexploited in the wildCVSS 9.8EPSS 94.2%
- CVE-2025-59374: "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized…criticalexploited in the wildCVSS 9.8EPSS 1.2%
- CVE-2023-39780: ASUS RT-AX55 OS command injection in start_apply.htmcriticalexploited in the wildCVSS 8.8EPSS 41.1%
- CVE-2025-15101: ASUS Router Firmware OS command injection in web management interfacehighCVSS 8.8
- CVE-2017-5632: ASUS RT-N56U denial of service in WAN connectionmediumCVSS 6.5
- CVE-2026-75754: ASUS Control Center missing authentication and hard-coded credentialsinfoCVSS 9.8EPSS 0.3%
- CVE-2026-13385: ASUS Router remote command execution via improper certificate validationinfoCVSS 9.5
- CVE-2026-8920: ASUS Aura Wallpaper Service path traversal and communication bypassinfoCVSS 8.5
- CVE-2026-8921: ASUS Business Manager privilege escalation via tampered IPC messageinfoCVSS 8.5
- CVE-2022-4989: ASUS AI Suite 3 privilege escalation in driverinfoCVSS 8.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 4 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 8 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 11 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/asus.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "ASUS vulnerabilities", https://junglewise.ai/threats/vendors/asus, 26 September 2026.