f5
1,024 tracked vulnerabilities.
CVE-2026-41219
MEDIUM
F5 BIG-IP QKView - Sensitive Information Disclosure
May 13, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-41218
HIGH
F5 BIG-IP PEM iRules - TMM Denial of Service
May 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-41217
HIGH
F5 BIG-IP tmsh - Privileged Command Execution
May 13, 2026
CVSS 7.9
EPSS 0.00
CVE-2026-40703
MEDIUM
BIG-IP 16.1.0-17.1.3.1 17.5.0-17.5.1.4 >=21.0.0 - Cross-Site Request Forgery in Dashboard
May 13, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-40701
MEDIUM
NGINX Plus and NGINX Open Source - Use-After-Free in ngx_http_ssl_module
May 13, 2026
CVSS 4.8
EPSS 0.00
CVE-2026-40699
MEDIUM
F5 BIG-IP 21.1.0-21.0.0.1, 17.5.0-17.5.1.4, 17.1.0-17.1.3.1, 16.1.0 - Authenticated Information Disclosure
May 13, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-40698
HIGH
F5 BIG-IP and BIG-IQ - Authenticated Privilege Escalation via SNMP Configuration Object Creation
May 13, 2026
CVSS 8.7
EPSS 0.00
CVE-2026-40631
HIGH
F5 BIG-IP 21.1.0-21.0.0.2 Authenticated Privilege Escalation via iControl SOAP
May 13, 2026
CVSS 8.7
EPSS 0.00
CVE-2026-40629
HIGH
F5 BIG-IP SSL/TLS - Virtual Server Denial of Service
May 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-40618
HIGH
F5 BIG-IP SSL/TLS - TMM Denial of Service
May 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-40462
MEDIUM
F5 BIG-IP 16.1.0-17.1.3.0 17.5.0-17.5.1.3 21.0.0-21.0.0 21.1.0+ - Authenticated Information Disclosure
May 13, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-40460
MEDIUM
NGINX Plus and Open Source - Authentication Bypass via HTTP/3 QUIC Module
May 13, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-40435
MEDIUM
F5 BIG-IP httpd - Access Control Bypass
May 13, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-40423
HIGH
F5 BIG-IP SIP Profile - TMM Denial of Service
May 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-40067
HIGH
F5 BIG-IP APM - apmd Denial of Service
May 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-40061
HIGH
BIG-IP 21.1.0-21.0.0.1 Authenticated Command Injection via iControl REST
May 13, 2026
CVSS 8.7
EPSS 0.00
CVE-2026-40060
HIGH
F5 BIG-IP Advanced WAF/ASM - bd Denial of Service
May 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-39459
HIGH
F5 - iControl REST and Tmsh Vulnerability
May 13, 2026
CVSS 7.2
EPSS 0.00
CVE-2026-39458
HIGH
F5 BIG-IP DNS Cache - TMM Denial of Service
May 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-39455
HIGH
BIG-IP 21.1.0+ 21.0.0-21.0.0.1 17.5.0-17.5.1.5 17.1.0-17.1.3.1 16.1.0 - Denial of Service via LDAP Authentication
May 13, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-35062
MEDIUM
F5 BIG-IP 21.1.0-21.0.0.1/17.5.1-17.5.1.4/17.1.0-17.1.3.1/16.1.0 Authenticated Info Disclosure via iControl SOAP
May 13, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-34176
HIGH
F5 BIG-IP 16.1.0-21.1.0 - Authenticated Remote Command Injection via iControl REST Endpoint
May 13, 2026
CVSS 8.7
EPSS 0.00
CVE-2026-34019
MEDIUM
F5 BIG-IP BFD - Routing Protocol Denial of Service
May 13, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-32673
HIGH
F5 BIG-IP 16.1.0-21.1.0 - Authenticated Privilege Escalation via Scripted Monitors
May 13, 2026
CVSS 8.7
EPSS 0.00
CVE-2026-32643
HIGH
F5 BIG-IP/BIG-IQ - Authenticated Command Execution
May 13, 2026
CVSS 8.7
EPSS 0.00
Products
big-ip_access_policy_manager 589
big-ip_application_security_manager 541
big-ip_advanced_firewall_manager 514
big-ip_local_traffic_manager 503
big-ip_policy_enforcement_manager 495
big-ip_link_controller 487
big-ip_application_acceleration_manager 486
big-ip_analytics 473
big-ip_global_traffic_manager 452
big-ip_domain_name_system 429
big-ip_fraud_protection_service 367
big-ip_webaccelerator 259
big-ip_edge_gateway 255
big-ip_advanced_web_application_firewall 155
big-ip_websafe 137
big-ip_ddos_hybrid_defender 127
big-ip_ssl_orchestrator 108
big-iq_centralized_management 77
big-ip_carrier-grade_nat 71
big-ip_application_visibility_and_reporting 70
big-ip_protocol_security_module 61
big-ip_container_ingress_services 48
big-ip_automation_toolchain 47
BIG-IP 46
nginx 41
enterprise_manager 39
njs 39
big-ip_wan_optimization_manager 38
traffix_signaling_delivery_controller 31
ssl_orchestrator 27
Quick Filters