Gigabyte Released Security Patch for Control Center

The update addresses critical vulnerabilities discovered in kernel drivers that could lead to system compromise.

Updated on Sept. 22, 2026 in Cybersecurity

Isometric editorial illustration of a silicon processor and circuit board trace with a digital lock, representing cybersecurity.
Gigabyte has released a security patch for its Control Center software to remediate critical kernel driver vulnerabilities that risked hardware manipulation. AI Illustration. Upload story photo >

Live Poll

Do you regularly update your computer software to protect against potential security vulnerabilities?

Gigabyte has issued a security update for its Control Center software to resolve multiple vulnerabilities found in its kernel drivers. These flaws could allow unauthorized users with local access to perform actions like direct hardware manipulation.

Why it matters

The patch is essential for preventing potential system-wide compromises caused by vulnerabilities in the IOCTL interfaces of the GVCIDrv64.sys and gdrv3.sys drivers. Fixing these issues prevents attackers from gaining unauthorized physical memory mapping access.

The security flaws carry a high CVSS rating of 8.8 out of 10, necessitating the transition to Control Center version 26.08.28.01. The vulnerabilities are specifically tied to improper input validation within kernel drivers.

The players

Gigabyte

Gigabyte is a global manufacturer of computer hardware and components including motherboards and graphics cards.

Mohamed Alzhrani

Mohamed Alzhrani is one of the security researchers credited with the discovery of the software vulnerabilities.

Subhan Sultanov

Subhan Sultanov is a security researcher who identified the flaws within the Gigabyte Control Center software.

The details

The vulnerabilities exist due to insufficient access control and improper validation of input parameters within the kernel drivers. By exploiting these weaknesses, an authenticated local attacker can bypass standard security protocols to perform unauthorized operations on the host system.

Timeline

  1. September 22, 2026: The security patch was released to the public.

The Big Picture

This patch follows the standard industry pattern of using the Common Vulnerability Scoring System (CVSS) framework to communicate the urgency of fixing kernel-level software vulnerabilities. It reflects the ongoing trend of securing hardware-linked software interfaces to prevent local escalation.

Users should update their Control Center software to version 26.08.28.01 immediately to ensure system integrity. Failure to patch may leave systems susceptible to unauthorized memory and hardware access if an attacker gains local machine access.

The takeaway

Maintaining updated software versions is a critical component of modern endpoint security for all PC users. Checking for vendor-supplied patches regularly helps mitigate the risk of local privilege escalation exploits.

Further reading

For more information on current digital threats, visit the Cybersecurity section.

Live Poll

Do you regularly update your computer software to protect against potential security vulnerabilities?