HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Unauthenticated RCE in ASUS Control Center Express Agent (CVE‑2026‑19397)

ASUS Control Center Express Agent is vulnerable to an unauthenticated remote code execution flaw (CVE‑2026‑19397) with a CVSS score of 9.8. The issue stems from a missing authentication check on the Remote Desktop endpoint (TCP 10637). Enterprises must patch promptly and reinforce access‑control evidence to satisfy audit and compliance expectations.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 zerodayinitiative.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Unauthenticated Remote Code Execution in ASUS Control Center Express Agent (CVE‑2026‑19397)

What It Is — ASUS Control Center Express Agent contains a missing‑authentication flaw in its Remote Desktop endpoint (TCP 10637). An unauthenticated remote attacker can execute arbitrary code in the context of the logged‑on console user.

Exploitability — The vulnerability is publicly disclosed, has a CVSS 9.8 score, and can be weaponized without any user interaction; no public exploit code has been observed yet, but the risk is high.

Affected Products — ASUS Control Center Express Agent (all versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Demonstrates a critical gap in access‑control safeguards; unauthenticated remote code execution bypasses identity verification entirely.
  • Highlights the need for continuous control monitoring to detect unexpected services (e.g., open port 10637) and to verify that remediation patches are applied promptly.
  • Provides a concrete audit‑ready evidence point: patch‑management logs and network‑segmentation controls become essential proof of due diligence for regulators and enterprise buyers.

Recommended Actions

  1. Deploy ASUS’s September 2026 security update immediately.
  2. Verify the agent version on all managed endpoints; enforce a minimum‑version policy.
  3. Block TCP 10637 at the network perimeter or restrict it to trusted management subnets.
  4. Integrate the patch‑status check into your continuous compliance monitoring platform.
  5. Update your access‑control policies to require authentication for any remote‑execution service.

Source: Zero Day Initiative Advisory – ZDI‑26‑657

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-657/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →