IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

F5 vulnerabilities

1039 CVE

F5 vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-5867 HIGH 8.1 f5 nginx_controller In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages 0.4% —
CVE-2022-25946 HIGH 8.7 f5 big-ip_access_policy_manager On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker with Administrator role 0.4% —
CVE-2026-42924 HIGH 8.7 f5 big-ip_access_policy_manager An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not e 0.4% —
CVE-2026-41953 HIGH 8.7 f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escalation.  Note: Software versions which have reached End of Tech 0.4% —
CVE-2026-40698 HIGH 8.7 f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege esca 0.4% —
CVE-2026-40631 HIGH 8.7 f5 big-ip_access_policy_manager An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evalua 0.4% —
CVE-2026-40061 HIGH 8.7 f5 big-ip_domain_name_system When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with 0.4% —
CVE-2026-32673 HIGH 8.7 f5 big-ip_access_policy_manager A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit c 0.4% —
CVE-2025-24497 HIGH 7.5 f5 big-ip_policy_enforcement_manager When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4% —
CVE-2025-24326 HIGH 7.5 f5 big-ip_application_security_manager When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0.4% —
CVE-2025-23412 HIGH 7.5 f5 big-ip_access_policy_manager When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4% —
CVE-2025-22846 HIGH 7.5 f5 big-ip_access_policy_manager When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.   Note: Software versions which have reached End of Technical Support (EoT 0.4% —
CVE-2025-21087 HIGH 7.5 f5 big-ip_access_policy_manager When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an increase in memory and CPU resource utilization. Note: Software versions which have reached End of Technical S 0.4% —
CVE-2025-20058 HIGH 7.5 f5 big-ip_access_policy_manager When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0.4% —
CVE-2025-20045 HIGH 7.5 f5 big-ip_access_policy_manager When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  N 0.4% —
CVE-2025-59268 MED 5.3 f5 big-ip_access_policy_manager On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated remote attacker through the Configuration utility.  Note: Software versions which have reached End of Technical Support (EoTS) are no 0.4% —
CVE-2023-29240 MED 5.4 f5 big-iq_centralized_management An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files using an undisclosed iControl REST endpoint.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4% —
CVE-2026-41954 MED 4.9 f5 big-ip_access_policy_manager Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.  Note: Software v 0.4% —
CVE-2022-23032 MED 5.3 f5 big-ip_access_policy_manager In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system, connecting BIG-IP Edge Client on Mac and Windows is vulnerable to a DNS rebinding attack. Note: Software versions which have reached End o 0.4% —
CVE-2026-34019 MED 5.3 f5 big-ip_access_policy_manager When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets and cause the configured routing protocol to fail over.  0.4% —
CVE-2025-24312 HIGH 7.5 f5 big-ip_advanced_firewall_manager When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed traffic can cause an increase in CPU resource utilization.   Note: Software versions which have re 0.4% —
CVE-2017-6142 MED 4.8 f5 big-ip_advanced_firewall_manager X509 certificate verification was not correctly implemented in the early access "user id" feature in the F5 BIG-IP Advanced Firewall Manager versions 13.0.0, 12.1.0-12.1.2, and 11.6.0-11.6.2, and thus did not properly validate the remote server's identity on c 0.4% —
CVE-2020-5909 MED 5.4 f5 nginx_controller In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified. 0.4% —
CVE-2020-5865 MED 4.8 f5 nginx_controller In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks. 0.4% —
CVE-2026-42063 MED 4.9 f5 big-ip_access_policy_manager A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator role can download sensitive files.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.4% —