ASUS has released security updates for Control Center Express and Armoury Crate on 8 September 2026 to fix a range of flaws. The most serious is CVE-2026-19397, a missing-authentication vulnerability in the Control Center Express Agent that could allow an unauthenticated nearby user to control the host when a login session is active. This has a CVSS v4 score of 7.7 (highest severity among the set) and is classified as CWE-306.
Separately, Armoury Crate contains a flaw, CVE-2026-12962, that can expose a user’s NTLM hash via a permissive cross-domain policy: a crafted web page can trigger a UNC-path request to a local service endpoint, leaking credentials. Other Armoury Crate driver issues require local access and IOCTL abuse to be exploited.
ASUS lists a total of 11 CVEs across both products, with 1 high, 9 medium and 1 low severity, and notes that there have been no confirmed active exploits at the time of the advisories. The affected versions include Control Center Express prior to v1.7.24 and older Armoury Crate builds and drivers. Users are urged to apply the latest updates immediately: upgrade Control Center Express to v1.7.24 or later and update Armoury Crate via its Update Centre. The company’s security advisory provides the full CVE list and steps for remediation.