Asus has released a critical BIOS update to address a local access vulnerability affecting several of its older motherboards designed for 8th and 9th Gen Intel processors. The vulnerability, identified as CVE-2026-93495, carries a high severity score of 7.0.
The security advisory from Asus explains that the flaw allows a physically proximate user to read or write arbitrary memory by inserting a specially crafted device. While exploitation requires physical access to the affected PC, the company strongly recommends that users update their BIOS to the latest available version to mitigate the risk.
A comprehensive list of affected motherboards, including various ROG Strix and ROG Maximus models, has been provided by Asus, along with the corresponding fixed BIOS versions. For some models, like the PRIME Z390-A and ROG MAXIMUS XI series, the fixed version is 2203, an update from previous versions through 2101. The WS Z390 PRO motherboard is updated to version 1502 from 1401.
Users can download the necessary updates from the Asus support website. The company also offers a guide on how to perform BIOS updates within Windows. This recent patch follows another high-severity security vulnerability discovered in August affecting Asus Armory Crate and other software tools.