CVE-2026-18023

Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mechanism. Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

  • Published Sep 8, 2026
  • CVSS 5.7 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-18023 at the National Vulnerability Database