Eye Security disclosed CVE-2026-75754, a critical unauthenticated remote-code-execution chain affecting ASUS Control Center through version 4.0.0.2. The chain exposed an encryption key, provided access to an Apache Guacamole servlet, and included a hardcoded root-password hash; an attacker could use Guacamole to SSH to localhost, bypass the appliance firewall, crack the root credential, and execute commands as root. ASUS released a patched version after disclosure. The researchers said Claude Opus 4.5 aided reverse engineering and exploit development, while human researchers identified and completed the exploitation path.
Separately, a researcher alleged that GPT-5.6-assisted analysis uncovered an unauthenticated WordPress exploit chain involving REST Batch API validation desynchronization, SQL injection in the posts REST endpoint, administrator-account creation, and eventual code execution through plugin upload. The reported chain relies on cache poisoning and WordPress customization and hook behaviors to elevate privileges and replay requests. No CVE, vendor advisory, fixed version, or confirmed patch was provided, so the WordPress findings remain unverified.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
WordPress introduced the REST Batch API in version 5.6. The later alleged exploit chain targets the Batch API endpoint at /wp-json/batch/v1.
After receiving the vulnerability report, ASUS released a patched version of ASUS Control Center for CVE-2026-75754.
Researchers identified CVE-2026-75754, a CVSS 10.0 chain affecting ASUS Control Center through version 4.0.0.2. The chain exposed an encryption key and Guacamole access, allowing an attacker to reach localhost SSH, authenticate as root using a cracked hardcoded-password hash, and execute commands as root.
A researcher alleged that a default WordPress installation using MySQL could be compromised without authentication by chaining Batch API request-validation desynchronization, SQL injection, cache poisoning, temporary administrator authority, and administrator-account creation. The report provides no CVE, vendor advisory, fixed version, or confirmed patch.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
research.eye.security
Open sourceslcyber.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.