CVE-2026-75754 affects ASUS Control Center Enterprise 4.0.0.2 and earlier. ASUS has published a security advisory for the vulnerability, and the ASUS-assigned CVE record describes a critical network-reachable flaw that can allow an unauthenticated attacker to gain root-level control of the ASUS Control Center server.
Current confirmed state: ASUS Control Center Enterprise 4.0.0.2 and earlier are affected by CVE-2026-75754. The vulnerability carries a CVSS v4.0 score of 10.0. TPS has not yet established the exact ASUS-fixed version or official remediation package from the primary material reviewed.
Which ASUS Control Center versions are affected?
ASUS identifies Control Center Enterprise 4.0.0.2 and earlier as affected by CVE-2026-75754. Administrators running one of those versions should treat the server as inside the vendor-confirmed affected range until they have checked the latest ASUS security guidance for the controlling remediation state.

How serious is CVE-2026-75754?
The ASUS-assigned CVE record gives the vulnerability a CVSS v4.0 score of 10.0. The recorded attack conditions show that the issue can be reached over the network without prior privileges or user interaction.
The described impact is especially important because ASUS Control Center Enterprise is a management platform. Successful exploitation can provide root-level control of the ACC server and may allow control over managed servers, PCs and workstations connected through that management environment.
What makes this different from a normal endpoint vulnerability?
The important distinction is the position of the affected software. ASUS Control Center Enterprise sits in a privileged management role. A flaw in that management layer can therefore have consequences beyond one workstation because the server may hold administrative control over other managed systems.
That does not mean every affected ACC installation has been compromised. TPS has not found evidence supporting that claim, and the number of affected or exposed installations remains unknown.
Is exploitation of CVE-2026-75754 confirmed?
No confirmed in-the-wild exploitation was established in the evidence reviewed by TPS. Current CVE enrichment reviewed during research did not show exploitation confirmation. This should not be interpreted as proof that exploitation is impossible or has never occurred; it means TPS does not currently have sufficient evidence to state that active exploitation has been confirmed.
What should an administrator verify now?
The safest evidence-backed first step is to determine the exact ASUS Control Center Enterprise version currently running. If the server is on 4.0.0.2 or earlier, it falls within the vendor-confirmed affected range.
Administrators should then consult the latest ASUS security advisory and product update guidance for the current remediation state. TPS has seen secondary sources claiming specific fixed versions, but those claims were not consistent enough to use as controlling vendor guidance in this article.
For that reason, this page intentionally does not name a fixed version that TPS cannot independently support from the primary ASUS material reviewed.
What is not confirmed yet?
The exact ASUS-fixed version or security package remains unresolved in the primary evidence reviewed by TPS. An official workaround for administrators who cannot update immediately was also not established.
TPS also has not established a complete indicator-of-compromise set, the number of exposed servers, India-specific deployment exposure or a confirmed exploitation campaign.
Why the exact remediation version matters
Knowing that 4.0.0.2 and earlier are affected does not automatically prove that any particular later version is the controlling fix. Security guidance can depend on a named release, hotfix, package or supported upgrade path. TPS therefore separates the confirmed affected-version boundary from the still-unresolved remediation boundary.
This article will be updated on the same URL when ASUS provides or exposes a sufficiently clear fixed-version, update-package or workaround state.
What should change this article next?
The most important next trigger is an ASUS update that identifies the exact fixed release or remediation package. A confirmed exploitation report, new compromise indicators, a CISA Known Exploited Vulnerabilities addition, a CERT-In advisory or a materially revised ASUS bulletin would also require immediate review.
Verification note: ThePulseSignal reviewed ASUS’s security advisory entry and the ASUS-assigned CVE record for the affected product, version boundary, attack conditions, severity and potential impact. Remediation details that could not be confirmed from the reviewed primary evidence are kept explicitly unresolved.



