Italian and Paraguayan government CERT advisories warned of three newly identified vulnerabilities affecting multiple Zyxel products, including numerous access points and the firewall and USG Flex lines. Two of the flaws were rated high severity and could allow attackers to execute arbitrary code or bypass security protections on affected devices, creating risk for organizations that rely on Zyxel networking and perimeter security equipment.
The advisories said the exposure spans specific firmware and ZLD version ranges and urged administrators to review Zyxel security bulletins and apply the recommended updates. Organizations using affected devices were advised to prioritize patching internet-exposed systems and verify that vulnerable access points, firewalls, and USG Flex appliances have been upgraded to fixed versions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The vendor-recommended mitigation is to update vulnerable Zyxel products and follow Zyxel security bulletins for remediation guidance. This response applies to the affected firmware and ZLD version ranges listed in the advisory.
Three newly identified vulnerabilities were reported in Zyxel products, including two rated high severity. The flaws affect multiple Zyxel access points, firewalls, and USG Flex product lines and could enable arbitrary code execution or security mechanism bypass.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.