CyberMax
Home › Exploited CVEs

Zyxel known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 13 Zyxel CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2026-09-21), and 2 are known to be used in ransomware campaigns.

Zyxel CVEs added to CISA KEV per year
2021: 1202112022: 2202222023: 6202362024: 1202412025: 2202522026: 120261

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Zyxel products

Multiple Firewalls (5), DSL CPE Devices (2), Multiple Network-Attached Storage (NAS) Devices (2), GS1900 Series Switches (1), EMG2926 Routers (1), P660HN-T1A Routers (1), Multiple Products (1).

All Zyxel CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-7273GS1900 Series SwitchesGS1900 Series Switches Stack-Based Buffer Overflow2026-09-212026-09-242.5%–
CVE-2024-40891DSL CPE DevicesDSL CPE OS Command Injection2025-02-112025-03-0421.5%–
CVE-2024-40890DSL CPE DevicesDSL CPE OS Command Injection2025-02-112025-03-0420.7%–
CVE-2024-11667Multiple FirewallsMultiple Firewalls Path Traversal2024-12-032024-12-242.9%Yes
CVE-2017-6884EMG2926 RoutersEMG2926 Routers Command Injection2023-09-182023-10-0934.4%Yes
CVE-2017-18368P660HN-T1A RoutersP660HN-T1A Routers Command Injection2023-08-072023-08-2894.4%–
CVE-2023-27992Multiple Network-Attached Storage (NAS) DevicesMultiple NAS Devices Command Injection2023-06-232023-07-1482.8%–
CVE-2023-33010Multiple FirewallsMultiple Firewalls Buffer Overflow2023-06-052023-06-2628.8%–
CVE-2023-33009Multiple FirewallsMultiple Firewalls Buffer Overflow2023-06-052023-06-2628.1%–
CVE-2023-28771Multiple FirewallsMultiple Firewalls OS Command Injection2023-05-312023-06-2199.3%–
CVE-2022-30525Multiple FirewallsMultiple Firewalls OS Command Injection2022-05-162022-06-0699.9%–
CVE-2020-9054Multiple Network-Attached Storage (NAS) DevicesMultiple NAS Devices OS Command Injection2022-03-252022-04-15100.0%–
CVE-2020-29583Multiple ProductsMultiple Products Use of Hard-Coded Credentials2021-11-032022-05-0390.2%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors