F5 Vulnerabilities and Affected Products
Vulnerabilities associated with BIG-IQ.
Products
Clear product- BIG-IP257 vulnerabilities
- NGINX Plus31 vulnerabilities
- NGINX Open Source29 vulnerabilities
- BIG-IP Next CNF26 vulnerabilities
- BIG-IP Next SPK23 vulnerabilities
- BIG-IQ19 vulnerabilities
- BIG-IP Next for Kubernetes13 vulnerabilities
- BIG-IP APM12 vulnerabilities
- F5OS - Appliance12 vulnerabilities
- BIG-IP Edge Client11 vulnerabilities
- F5OS - Chassis10 vulnerabilities
- BIG-IP Next Central Manager9 vulnerabilities
- BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator)8 vulnerabilities
- BIG-IQ Centralized Management7 vulnerabilities
- big-ip_next_central_manager6 vulnerabilities
- nginx6 vulnerabilities
- NGINX Ingress Controller5 vulnerabilities
- NGINX Instance Manager5 vulnerabilities
- nginx_plus5 vulnerabilities
- BIG-IP Guided Configuration (GC)4 vulnerabilities
- BIG-IP Next4 vulnerabilities
- F5OS-A4 vulnerabilities
- BIG-IP Advanced WAF & ASM3 vulnerabilities
- BIG-IP AFM3 vulnerabilities
- BIG-IP APM Clients3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-41959HIGH | iControl and tmsh REST vulnerabilityIncorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view the network status of destination systems. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-732May 13, 2026 | CVSS7.1v4.0 | EPSS0.203% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42406HIGH | BIG-IP and BIG-IQ privilege escalation vulnerabilityA vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-267May 13, 2026 | CVSS8.5v4.0 | EPSS0.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32643HIGH | BIG-IP and BIG-IQ privilege escalation vulnerabilityA vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-250May 13, 2026 | CVSS8.5v4.0 | EPSS0.156% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42937HIGH | iControl REST and tmsh vulnerabilityIncorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view adjacent network information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-732May 13, 2026 | CVSS7.1v4.0 | EPSS0.203% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40698HIGH | iControl REST and TMSH vulnerabilityA vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-77May 13, 2026 | CVSS8.5v4.0 | EPSS0.235% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20916HIGH | BIG-IQ iControl REST vulnerabilityAn authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-22May 13, 2026 | CVSS7.2v4.0 | EPSS0.366% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-41957HIGH | BIG-IP and BIG-IQ Configuration utility vulnerabilityAn authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-502May 13, 2026 | CVSS8.7v4.0 | EPSS0.514% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-41219HIGH | Generated title:BIG-IP QKView Improper Sanitization Information DisclosureAn improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated CWE-532May 13, 2026 | CVSS7.1v4.0 | EPSS0.277% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-41954MEDIUM | iControl REST and tmsh vulnerabilitySensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-200May 13, 2026 | CVSS6.9v4.0 | EPSS0.294% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-47139MEDIUM | F5 BIG-IQ VulnerabilityA stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-80Oct 16, 2024 | CVSS4.8v4.0 | EPSS0.547% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21782MEDIUM | BIG-IP and BIG-IQ secure copy vulnerabilityBIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) can execute arbitrary commands with a specially crafted command string. This vulnerability is due to an incomplete fix for CVE-2020-5873. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated CWE-78Feb 14, 2024 | CVSS6.7v3.1 | EPSS0.178% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-43485MEDIUM | BIGIP and BIG-IQ TACACS+ audit log VulnerabilityWhen TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-532Oct 10, 2023 | CVSS5.5v3.1 | EPSS0.171% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41964MEDIUM | BIG-IP and BIG-IQ Database Variable vulnerabilityThe BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-312Oct 10, 2023 | CVSS4.3v3.1 | EPSS0.244% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-38419MEDIUM | BIG-IP and BIG-IQ iControl SOAP vulnerabilityAn authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. CWE-755Aug 2, 2023 | CVSS4.3v3.1 | EPSS0.547% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-29240MEDIUM | BIG-IQ iControl REST VulnerabilityAn authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS5.4v3.1 | EPSS0.405% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-41770MEDIUM | BIG-IP and BIG-IQ iControl REST vulnerability CVE-2022-41770In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ all versions of 8.x and 7.x, an authenticated iControl REST user can cause an increase in memory resource utilization, via undisclosed requests. CWE-400Oct 19, 2022 | CVSS6.5v3.1 | EPSS0.612% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-41694MEDIUM | BIG-IP and BIG-IQ mcpd vulnerability CVE-2022-41694In BIG-IP versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, and BIG-IQ versions 8.x before 8.2.0.1 and all versions of 7.x, when an SSL key is imported on a BIG-IP or BIG-IQ system, undisclosed input can cause MCPD to terminate. CWE-20Oct 19, 2022 | CVSS4.9v3.1 | EPSS0.611% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-6688MEDIUM | On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5 and BIG-IQ versions 6.0.0-6.1.0 and 5.2.0-5.4.0, a user is able to obtain the secret that was being used to encrypt a BIG-IP UCS backup file while sending SNMP query to the BIG-IP or BIG-IQ system, however the user can not access to the UCS files. Dec 23, 2019 | CVSS4.3v3.1 | EPSS0.697% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-6665CRITICAL | On BIG-IP ASM 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, BIG-IQ 6.0.0 and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, an attacker with access to the device communication between the BIG-IP ASM Central Policy Builder and the BIG-IQ/Enterprise Manager/F5 iWorkflow will be able to set up the proxy the same way and intercept the traffic. Nov 27, 2019 | CVSS9.4v3.1 | EPSS1.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |