boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Zyxel

Vendor reference — Zyxel · sector: Network & Infrastructure. Cumulative disclosure record across the archive.

Follow Zyxel — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs198
KEV entries110
Rate & severity
KEV/100Med CVSSMed EPSSCHML
57.97.2.21831440

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▃▁▁▁▃▁▃▁▁▁▁▁▁▁▁▁▁▁▃█▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▆▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃█▃█

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-051
2026-063
2026-071
2026-083

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2020-9054100.0YES2022-03-25
CVE-2022-30525100.0YES2022-05-16
CVE-2023-2877199.9YES2023-05-31
CVE-2017-1836899.8YES2023-08-07
CVE-2020-2958399.8YES2021-11-03
CVE-2023-2799299.7YES2023-06-23
CVE-2023-3301098.0YES2023-06-05
CVE-2023-3300998.0YES2023-06-05
CVE-2024-4089097.5YES2025-02-11
CVE-2024-4089197.4YES2025-02-11
CVE-2024-116679.886.4CRITICALYES2024-12-03
CVE-2026-68377.258.5HIGH2026-08-04
CVE-2026-69527.258.5HIGH2026-07-21
CVE-2026-85086.543.3MEDIUM2026-08-04
CVE-2026-148187.229.1HIGH2026-08-04

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-68377.258.5HIGH2026-08-04
CVE-2026-85086.543.3MEDIUM2026-08-04
CVE-2026-148187.229.1HIGH2026-08-04
CVE-2026-69527.258.5HIGH2026-07-21
CVE-2026-72738.824.3HIGH2026-06-16
CVE-2026-38716.56.6MEDIUM2026-06-02
CVE-2026-38706.56.6MEDIUM2026-06-02
CVE-2026-47956.514.5MEDIUM2026-05-26
CVE-2024-4089097.5YES2025-02-11
CVE-2024-4089197.4YES2025-02-11
CVE-2024-116679.886.4CRITICALYES2024-12-03
CVE-2017-1836899.8YES2023-08-07
CVE-2023-2799299.7YES2023-06-23
CVE-2023-3301098.0YES2023-06-05
CVE-2023-3300998.0YES2023-06-05

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
Multiple Firewalls44
ATP Series Firmware21
DSL CPE Devices22
Multiple Network-Attached Storage (NAS) Devices22
USG FLEX 50(W) Series Firmware21
USG FLEX Series Firmware21
USG20(W)-VPN Series Firmware21
VMG4005-B50B Firmware20
WAX650S Firmware20

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2024-408902025-02-1197.5
CVE-2024-408912025-02-1197.4
CVE-2024-116672024-12-039.886.4CRITICAL
CVE-2017-183682023-08-0799.8
CVE-2023-279922023-06-2399.7
CVE-2023-330102023-06-0598.0
CVE-2023-330092023-06-0598.0
CVE-2023-287712023-05-3199.9
CVE-2022-305252022-05-16100.0
CVE-2020-90542022-03-25100.0
CVE-2020-295832021-11-0399.8

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2020-90542022-04-151587
CVE-2020-295832022-05-031569
CVE-2022-305252022-06-061535
CVE-2023-287712023-06-211155
CVE-2023-330092023-06-261150
CVE-2023-330102023-06-261150
CVE-2023-279922023-07-141132
CVE-2017-183682023-08-281087
CVE-2024-116672024-12-24603
CVE-2024-408912025-03-04533

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.