ASUS released an urgent update for ASUS Control Center Enterprise (ACC) to remediate CVE-2026-75754, a maximum-severity vulnerability rated CVSS 4.0 10.0. The flaw chains missing authentication, server-side request forgery (SSRF), exposure of an encryption key, and embedded credentials, allowing an unauthenticated remote attacker to gain root-level control of an ACC server.
Compromise of an ACC instance could give an attacker administrative control over centrally managed servers, PCs, and workstations. ACC versions through 4.0.0.2 are affected; ASUS advises updating to version 3.1.0.9 or later. Organizations unable to patch immediately should isolate ACC management interfaces, restrict SSH traffic on TCP port 2222, and investigate unexpected SSH listeners.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
ASUS disclosed CVE-2026-75754 in ASUS Control Center Enterprise and issued an urgent security update. The CVSS 4.0 10.0 flaw affects ACC versions through 4.0.0.2 and can allow unauthenticated remote attackers to obtain root access through a missing-authentication, SSRF, encryption-key retrieval, SSH, and hard-coded-credential chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.