cbcvebase.

F5 Big-Ip vulnerabilities

406 known vulnerabilities affecting f5/big-ip.

Total CVEs
406
CISA KEV
4
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH171MEDIUM74LOW5UNKNOWN148

Vulnerabilities

Page 2 of 21
CVE-2026-35062HIGHCVSS 7.1≥ 21.0.0, < 21.0.0.1≥ 17.5.1, < 17.5.1.4+2 more2026-05-13
CVE-2026-35062 [HIGH] CWE-266 CVE-2026-35062: An authenticated iControl SOAP user may be able to obtain information of other accounts.  Note: Sof An authenticated iControl SOAP user may be able to obtain information of other accounts. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42781HIGHCVSS 7.1≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+1 more2026-05-13
CVE-2026-42781 [HIGH] CWE-835 CVE-2026-42781: When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethe When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-41959HIGHCVSS 7.1≥ 21.0.0, < 21.0.0.2≥ 17.5.0, < 17.5.1.6+2 more2026-05-13
CVE-2026-41959 [HIGH] CWE-732 CVE-2026-41959: Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view the network status of destination systems. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
nvd
CVE-2026-42409HIGHCVSS 8.7≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-42409 [HIGH] CWE-476 CVE-2026-42409: When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are confi When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-41218HIGHCVSS 8.7≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-41218 [HIGH] CWE-416 CVE-2026-41218: When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASS When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40061HIGHCVSS 8.5≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-40061 [HIGH] CWE-77 CVE-2026-40061: When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TM When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker
nvd
CVE-2026-34176HIGHCVSS 8.5≥ 21.0.0, < 21.0.0.2≥ 17.5.0, < 17.5.1.6+2 more2026-05-13
CVE-2026-34176 [HIGH] CWE-78 CVE-2026-34176: When running in Appliance mode, an authenticated remote command injection vulnerability exists in an When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-41225HIGHCVSS 8.6≥ 21.0.0, < 21.0.0.2≥ 17.5.0, < 17.5.1.6+2 more2026-05-13
CVE-2026-41225 [HIGH] CWE-648 CVE-2026-41225: A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at le A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-39459HIGHCVSS 8.6≥ 21.0.0, < 21.0.0.2≥ 17.5.0, < 17.5.1.6+2 more2026-05-13
CVE-2026-39459 [HIGH] CWE-272 CVE-2026-39459: A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authent A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40699HIGHCVSS 7.1≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-40699 [HIGH] CWE-643 CVE-2026-40699: A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-pr A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticated attacker to access to undisclosed sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-41227HIGHCVSS 8.7≥ 17.5.0, < 17.5.1.4≥ 17.1.0, < 17.1.3.1+1 more2026-05-13
CVE-2026-41227 [HIGH] CWE-770 CVE-2026-41227: On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result i On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40698HIGHCVSS 8.5≥ 21.0.0, < 21.0.0.2≥ 17.5.0, < 17.5.1.6+2 more2026-05-13
CVE-2026-40698 [HIGH] CWE-77 CVE-2026-40698: A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacke A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not eva
nvd
CVE-2026-40067HIGHCVSS 8.7≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-40067 [HIGH] CWE-120 CVE-2026-40067: When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40060HIGHCVSS 8.7≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-40060 [HIGH] CWE-252 CVE-2026-40060: When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed req When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-28758MEDIUMCVSS 6.7≥ 17.5.0, < 17.5.1.4≥ 17.1.0, < 17.1.3.1+1 more2026-05-13
CVE-2026-28758 [MEDIUM] CWE-312 CVE-2026-28758: When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST co When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is also logged in the audit log. This may allow a highly privileged, authenticated attacker with access to the audit log to view sensitive information. Note:
nvd
CVE-2026-24464MEDIUMCVSS 6.9≥ 21.0.0, < 21.0.0.2≥ 17.5.0, < 17.5.1.6+2 more2026-05-13
CVE-2026-24464 [MEDIUM] CWE-35 CVE-2026-24464: When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iContro When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40435MEDIUMCVSS 6.9≥ 17.5.0, < 17.5.1.4≥ 17.1.0, < 17.1.3.1+1 more2026-05-13
CVE-2026-40435 [MEDIUM] CWE-420 CVE-2026-40435: When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40703MEDIUMCVSS 5.3≥ 17.5.0, < 17.5.1.4≥ 17.1.0, < 17.1.3.1+1 more2026-05-13
CVE-2026-40703 [MEDIUM] CWE-352 CVE-2026-40703: A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuratio A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvdf5
CVE-2026-42780MEDIUMCVSS 6.9≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.5+2 more2026-05-13
CVE-2026-42780 [MEDIUM] CWE-22 CVE-2026-42780: A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated a A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvdf5
CVE-2026-42058MEDIUMCVSS 5.3≥ 21.0.0, < 21.0.0.2≥ 17.5.0, < 17.5.1.6+2 more2026-05-13
CVE-2026-42058 [MEDIUM] CWE-732 CVE-2026-42058: An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
F5 Big-Ip vulnerabilities | cvebase