PatchSiren

ASUSTOR Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ASUSTOR Inc. CVE published 2026-08-04

CVE-2026-18759

The CVE-2026-18759 vulnerability affects the background service of ABP (ASUSTOR Backup Plan) and AES (ASUSTOR EZSync), which run as NT AUTHORITY SYSTEM. These services implement a file-based inter-process communication (IPC) mechanism protected by AES encryption. However, the encryption key file is readable by standard users and protected using DPAPI, allowing authenticated local users to recover the key [truncated]