42
30
30
47
47
47
60
55
Week in review: Exploited newly patched BeyondTrust RCE, United Airlines CISO on building resilience
60
30
60
55
60
60
55
30
42
30
60
30
60
60
60
55
60
55
47
60
55
47
60
42
35
55
55
60
30
30
30
ASUS Control Center Critical Flaw Allows Unauthenticated Attackers to Gain Root Access
ASUS patched CVE-2026-19397 (CVSS 7.7) in Control Center Express Agent, letting unauthenticated nearby attackers with an active session take over the host.
ASUS released version 1.7.24 of Control Center Express Agent to fix CVE-2026-19397, a CWE-306 missing-authentication flaw scored 7.7 on CVSS v4. Exploitation requires an active login session on the target and nearby network access, and agent compromise could lead to complete device takeover where the agent runs with elevated privileges. ASUS also issued a same-day advisory for Armory Crate covering ten additional CVEs.
62