Exploited CVEs / By vendor / Zyxel

Zyxel vulnerabilities actively exploited

12 Zyxel CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2024-40890 (DSL CPE Devices, added 2025-02-11). 2 of the 12 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

12 exploited CVEs2 ransomware-linked
Senserva AI Opinion and rich prompt for Zyxel exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

Multiple Firewalls: 5 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2024-11667Multiple Firewalls2024-12-03ransomware, CVSS 9.8, EPSS 3%
CVE-2023-33009Multiple Firewalls2023-06-05CVSS 9.8, EPSS 28%
CVE-2023-33010Multiple Firewalls2023-06-05CVSS 9.8, EPSS 29%
CVE-2023-28771Multiple Firewalls2023-05-31CVSS 9.8, EPSS 99%
CVE-2022-30525Multiple Firewalls2022-05-16CVSS 9.8, EPSS 100%

Other Zyxel products

CVEProductAdded to KEVSignals
CVE-2024-40890DSL CPE Devices2025-02-11CVSS 8.8, EPSS 22%
CVE-2024-40891DSL CPE Devices2025-02-11CVSS 8.8, EPSS 22%
CVE-2017-6884EMG2926 Routers2023-09-18ransomware, CVSS 8.8, EPSS 38%
CVE-2017-18368P660HN-T1A Routers2023-08-07CVSS 9.8, EPSS 95%
CVE-2023-27992Multiple Network-Attached Storage (NAS) Devices2023-06-23CVSS 9.8, EPSS 84%
CVE-2020-9054Multiple Network-Attached Storage (NAS) Devices2022-03-25CVSS 9.8, EPSS 100%
CVE-2020-29583Multiple Products2021-11-03CVSS 9.8, EPSS 90%

Common questions about exploited Zyxel CVEs

Which Zyxel vulnerabilities are actively exploited?

As of August 2026, 12 Zyxel CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are Multiple Firewalls (5). 2 are linked to ransomware campaigns.

What is the newest exploited Zyxel CVE?

CVE-2024-40890, affecting DSL CPE Devices, added to the CISA KEV catalog on 2025-02-11. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these Zyxel CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited Zyxel CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest Zyxel KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.