CVE-2026-8918: ASUS Armoury Crate

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS Armoury Crate: up to and including 6.4.12

Published 2026-06-22. Last modified 2026-09-17.