THE ESSENTIALS
  • Reported impacts are operating-system crashes and forced reboots.

What changed

TWCERT/CC disclosed two vulnerabilities in ASRock Polychrome SYNC/RGB. CVE-2026-90890 can crash the operating system through an unchecked pointer; CVE-2026-90891 can force a reboot through inadequately restricted hardware-port writes. Both require an authenticated local attacker. Affected editions include motherboard software through 1.0.118 and graphics-card software through 2.0.219.

Why it matters

The disclosures show why peripheral-management utilities belong in software inventories. Although the reported impact is availability, an attacker who already has a local account could interrupt work through a component installed primarily to control lighting.

What remains unproven

The notice does not report exploitation in the wild or identify the first fixed build. It directs users to versions above those affected thresholds; it does not establish remote compromise or data theft.

THE EVIDENCE RECORD

Read beyond this page.

Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.

  1. TWCERT/CC ↗
Changes & version history

Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review

Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release

Version 1 · 15 Sep 2026
Source-linked private review edition

Request a correction ↗