f5
1,024 tracked vulnerabilities.
CVE-2026-9256
HIGH
F5 NGINX Plus - NGINX ngx_http_rewrite_module Vulnerability
May 22, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-8711
HIGH
NGINX JavaScript vulnerability
May 19, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-42946
MEDIUM
NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability
May 13, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-42945
HIGH
NGINX Plus and NGINX Open Source - Heap-based Buffer Overflow in ngx_http_rewrite_module
May 13, 2026
CVSS 8.1
EPSS 0.01
CVE-2026-42937
MEDIUM
F5 BIG-IP and BIG-IQ - Authenticated Information Disclosure via TMOS Shell arp/ndp Commands and iControl REST
May 13, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-42934
MEDIUM
NGINX Plus and NGINX Open Source - Out-of-bounds Read in ngx_http_charset_module
May 13, 2026
CVSS 4.8
EPSS 0.00
CVE-2026-42930
HIGH
F5 BIG-IP 16.1.0-21.1.0 - Authenticated Appliance Mode Restriction Bypass
May 13, 2026
CVSS 8.7
EPSS 0.00
CVE-2026-42926
MEDIUM
NGINX Open Source 1.29.4-1.30.0 and >=1.31.0 - HTTP/2 Request Smuggling via proxy_set_body
May 13, 2026
CVSS 5.8
EPSS 0.00
CVE-2026-42924
HIGH
F5 BIG-IP 16.1.0-21.1.0 - Authenticated Privilege Escalation via SNMP Configuration Object
May 13, 2026
CVSS 8.7
EPSS 0.00
CVE-2026-42920
HIGH
F5 BIG-IP DTLS - TMM Denial of Service
May 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-42919
MEDIUM
F5 BIG-IP Appliance Mode Vulnerability
May 13, 2026
CVSS 6.7
EPSS 0.00
CVE-2026-42781
MEDIUM
F5 BIG-IP 16.1.0-21.1.0 - Denial of Service via ePVA Ethernet Traffic
May 13, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-42780
MEDIUM
BIG-IP SSL Orchestrator - Authenticated Path Traversal and Arbitrary File Write
May 13, 2026
CVSS 4.9
EPSS 0.00
CVE-2026-42409
HIGH
F5 BIG-IP HTTP/2 iRule - TMM Denial of Service
May 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-42408
MEDIUM
F5 BIG-IP DNS tmsh - Sensitive Information Disclosure
May 13, 2026
CVSS 4.4
EPSS 0.00
CVE-2026-42406
HIGH
F5 BIG-IP/BIG-IQ - Authenticated Privilege Escalation
May 13, 2026
CVSS 8.7
EPSS 0.00
CVE-2026-42063
MEDIUM
F5 BIG-IP 16.1.0-21.1.0 - Authenticated Sensitive File Download via iControl SOAP
May 13, 2026
CVSS 4.9
EPSS 0.00
CVE-2026-42058
MEDIUM
F5 BIG-IP 16.1.0-21.1.0 - Authenticated Information Disclosure via iControl REST
May 13, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-41959
MEDIUM
F5 BIG-IP and BIG-IQ - Authenticated Information Disclosure via TMOS Shell and iControl REST
May 13, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-41957
HIGH
F5 - BIG-IP and BIG-IQ Configuration Utility Vulnerability
May 13, 2026
CVSS 8.8
EPSS 0.01
CVE-2026-41956
HIGH
F5 BIG-IP UDP Classification Profile - TMM Denial of Service
May 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-41954
MEDIUM
F5 - iControl REST and Tmsh Vulnerability
May 13, 2026
CVSS 4.9
EPSS 0.00
CVE-2026-41953
HIGH
F5 BIG-IP 16.1.0-17.1.3.1/17.5.0-17.5.1.5/21.0.0-21.0.0.1/>=21.1.0 Privilege Escalation via Config Modification
May 13, 2026
CVSS 8.7
EPSS 0.00
CVE-2026-41227
HIGH
BIG-IP HTTP/2 Layer 7 Dos Protection vulnerability
May 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-41225
CRITICAL
F5 BIG-IP 16.1.0-17.1.3.1/17.5.0-17.5.1.5/21.0.0-21.0.0.1/>=21.1.0 - Authenticated RCE via iControl REST
May 13, 2026
CVSS 9.1
EPSS 0.00
Products
big-ip_access_policy_manager 589
big-ip_application_security_manager 541
big-ip_advanced_firewall_manager 514
big-ip_local_traffic_manager 503
big-ip_policy_enforcement_manager 495
big-ip_link_controller 487
big-ip_application_acceleration_manager 486
big-ip_analytics 473
big-ip_global_traffic_manager 452
big-ip_domain_name_system 429
big-ip_fraud_protection_service 367
big-ip_webaccelerator 259
big-ip_edge_gateway 255
big-ip_advanced_web_application_firewall 155
big-ip_websafe 137
big-ip_ddos_hybrid_defender 127
big-ip_ssl_orchestrator 108
big-iq_centralized_management 77
big-ip_carrier-grade_nat 71
big-ip_application_visibility_and_reporting 70
big-ip_protocol_security_module 61
big-ip_container_ingress_services 48
big-ip_automation_toolchain 47
BIG-IP 46
nginx 41
enterprise_manager 39
njs 39
big-ip_wan_optimization_manager 38
traffix_signaling_delivery_controller 31
ssl_orchestrator 27
Quick Filters