<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/marques/zyxel.xml</id>
  <title>Exploit Radar: exploited Zyxel vulnerabilities</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities for Zyxel products.</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/marques/zyxel.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/marques/zyxel/"/>
  <updated>2026-09-21T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-7273/</id>
    <title>CVE-2026-7273 — Zyxel Switches (GS, XGS)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-7273/"/>
    <updated>2026-09-21T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Zyxel; if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Added to CISA’s catalog of exploited vulnerabilities on September 21, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-40890/</id>
    <title>CVE-2024-40890 — Zyxel Home gateways and routers (DSL, CPE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-40890/"/>
    <updated>2025-02-11T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Zyxel; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on February 11, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-40891/</id>
    <title>CVE-2024-40891 — Zyxel Home gateways and routers (DSL, CPE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-40891/"/>
    <updated>2025-02-11T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Zyxel; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on February 11, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-11667/</id>
    <title>CVE-2024-11667 — Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-11667/"/>
    <updated>2024-12-03T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Zyxel; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on December 3, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2017-6884/</id>
    <title>CVE-2017-6884 — Zyxel Home gateways and routers (DSL, CPE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2017-6884/"/>
    <updated>2023-09-18T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Zyxel; if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on September 18, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2017-18368/</id>
    <title>CVE-2017-18368 — Zyxel Home gateways and routers (DSL, CPE)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2017-18368/"/>
    <updated>2023-08-07T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Zyxel; if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on August 7, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-27992/</id>
    <title>CVE-2023-27992 — Zyxel NAS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-27992/"/>
    <updated>2023-06-23T00:00:00Z</updated>
    <summary type="text">Apply the security update from Zyxel. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on June 23, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-33009/</id>
    <title>CVE-2023-33009 — Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-33009/"/>
    <updated>2023-06-05T00:00:00Z</updated>
    <summary type="text">Apply the security update from Zyxel. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on June 5, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-33010/</id>
    <title>CVE-2023-33010 — Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-33010/"/>
    <updated>2023-06-05T00:00:00Z</updated>
    <summary type="text">Apply the security update from Zyxel. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on June 5, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-28771/</id>
    <title>CVE-2023-28771 — Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-28771/"/>
    <updated>2023-05-31T00:00:00Z</updated>
    <summary type="text">Apply the security update from Zyxel. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on May 31, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-30525/</id>
    <title>CVE-2022-30525 — Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-30525/"/>
    <updated>2022-05-16T00:00:00Z</updated>
    <summary type="text">Apply the security update from Zyxel. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on May 16, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-9054/</id>
    <title>CVE-2020-9054 — Zyxel NAS</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-9054/"/>
    <updated>2022-03-25T00:00:00Z</updated>
    <summary type="text">Apply the security update from Zyxel. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 25, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-29583/</id>
    <title>CVE-2020-29583 — Zyxel Firewalls (ATP, USG FLEX, ZyWALL/USG)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-29583/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Zyxel. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
</feed>
