CVE Tools

Asus

278 CVEs tracked since 2005. Since Nov 2005, 1 of them reached CISA KEV.

Asus CVEs per month

Nov 2005 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Asus CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2005-1120
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-0310
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-0210
2009-03null or fewer
2009-04null or fewer
2009-05null or fewer
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-0930
2009-10null or fewer
2009-11null or fewer
2009-12null or fewer
2010-01null or fewer
2010-02null or fewer
2010-03null or fewer
2010-04null or fewer
2010-05null or fewer
2010-06null or fewer
2010-07null or fewer
2010-08null or fewer
2010-09null or fewer
2010-10null or fewer
2010-11null or fewer
2010-12null or fewer
2011-01null or fewer
2011-02null or fewer
2011-03null or fewer
2011-04null or fewer
2011-05null or fewer
2011-06null or fewer
2011-07null or fewer
2011-08null or fewer
2011-09null or fewer
2011-10null or fewer
2011-1110
2011-12null or fewer
2012-01null or fewer
2012-02null or fewer
2012-03null or fewer
2012-04null or fewer
2012-05null or fewer
2012-06null or fewer
2012-07null or fewer
2012-08null or fewer
2012-0910
2012-10null or fewer
2012-11null or fewer
2012-12null or fewer
2013-01null or fewer
2013-02null or fewer
2013-03null or fewer
2013-04null or fewer
2013-05null or fewer
2013-06null or fewer
2013-0710
2013-08null or fewer
2013-09null or fewer
2013-1010
2013-11null or fewer
2013-12null or fewer
2014-0120
2014-02null or fewer
2014-03null or fewer
2014-0430
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-1110
2014-12null or fewer
2015-0110
2015-0230
2015-0320
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-0910
2015-10null or fewer
2015-11null or fewer
2015-1240
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-0340
2017-04null or fewer
2017-0540
2017-06null or fewer
2017-07null or fewer
2017-0830
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-0180
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-0730
2018-0820
2018-0960
2018-1020
2018-11null or fewer
2018-1250
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-0550
2019-06null or fewer
2019-07null or fewer
2019-0830
2019-0920
2019-10null or fewer
2019-11280
2019-1240
2020-0120
2020-0220
2020-0340
2020-04null or fewer
2020-05null or fewer
2020-0620
2020-07null or fewer
2020-0820
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-1220
2021-0120
2021-0240
2021-03null or fewer
2021-04380
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-1140
2021-12null or fewer
2022-0140
2022-02null or fewer
2022-0340
2022-04100
2022-05null or fewer
2022-0640
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-1040
2022-11null or fewer
2022-12null or fewer
2023-0130
2023-0250
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-0660
2023-0760
2023-08null or fewer
2023-09101
2023-10null or fewer
2023-1150
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-0680
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-0140
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11110
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06null or fewer
2026-07130
2026-08null or fewer
2026-09120

Products

The products that kept showing up in Asus's monthly top three, with their CVEs summed over those months.

  1. Bmc Firmware For ASMB8-IKVM181 month
  2. Bmc Firmware For Z10PR-D16181 month
  3. Z10PR-D16 Firmware181 month
  4. Armoury Crate123 months
  5. Rt-ax55 Firmware113 months
  6. Router102 months
  7. Rt-ac68u Firmware104 months
  8. Rt-ac86u103 months
  9. Rt-ac86u Firmware102 months
  10. Asuswrt92 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Asus.

  1. CVE-2026-19397Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has ...—
  2. CVE-2026-12962A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sen...—
  3. CVE-2026-18023Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request t...—
  4. CVE-2026-16003Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing ...—
  5. CVE-2026-16004Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the drive...—
  6. CVE-2026-16005Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt da...—
  7. CVE-2026-16006Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing t...—
  8. CVE-2026-75808Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentic...—
  9. CVE-2026-75809Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using I...—
  10. CVE-2026-75810Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management int...—
  11. CVE-2026-75811Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypass...—
  12. CVE-2026-75754Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key v...—
  13. CVE-2026-19398An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SM...—
  14. CVE-2026-8917Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, pote...—
  15. CVE-2026-16727Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a cr...—

The record

Peak rank
#20 in Apr 2021
Busiest month shown
Apr 2021, 38 CVEs
Months with a KEV entry
1 since Nov 2005
Monthly snapshots
56 since 2005
Asus's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store