CVE-2026-4415: GIGABYTE Control Center

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation.

Affected products

  • GIGABYTE Control Center: before 25.12.10.01 (fixed in 25.12.10.01)

Published 2026-03-30. Last modified 2026-06-17.