CVE-2026-15030: ASUS Business Manager

Medium severity, CVSS 5.6. EPSS: 0.1% chance of exploitation in the next 30 days.

Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to the ' Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS Business Manager: up to and including v3.0.38.0
  • ASUS System Control Interface: before v1.1.40.0 (fixed in v1.1.40.0)
  • ASUS System Control Interface v3: before v3.1.65.0 (fixed in v3.1.65.0)

Published 2026-07-15. Last modified 2026-09-17.