F5 Big-Ip vulnerabilities
261 known vulnerabilities affecting f5/big-ip.
Total CVEs
261
CISA KEV
4
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH159MEDIUM88LOW5
Vulnerabilities
Page 3 of 14
CVE-2026-39455P3HIGHCVSS 7.5≥ 21.0.0, < 21.0.0.2≥ 17.5.0, < 17.5.1.6+2 more2026-05-13
CVE-2026-39455 [HIGH] CWE-772 CVE-2026-39455: When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LD
When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-41218P3HIGHCVSS 7.5≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-41218 [HIGH] CWE-416 CVE-2026-41218: When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASS
When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2024-28883P3HIGHCVSS 7.4≥ 17.1.0, < 17.1.1≥ 16.1.0, < 16.1.4.2+1 more2024-05-08
CVE-2024-28883 [HIGH] CWE-346 CVE-2024-28883: An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for
An origin validation vulnerability exists in
BIG-IP APM browser network access VPN client
for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2022-26071P3HIGHCVSS 7.5v12.1.xv11.6.x+4 more2022-05-05
CVE-2022-26071 [HIGH] CWE-330 CVE-2022-26071: On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions p
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a flaw in the way reply ICMP packets are limited in the Traffic Management Microkernel (TMM) allows an attacker to quickly scan open UDP ports. This flaw allows an
nvd
CVE-2025-46706P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.2.2≥ 16.1.0, < 16.1.62025-10-15
CVE-2025-46706 [HIGH] CWE-770 CVE-2025-46706: When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed re
When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2019-6622P3HIGHCVSS 7.2vBIG-IP 14.1.0-14.1.0.5v14.0.0-14.0.0.5+3 more2019-07-02
CVE-2019-6622 [HIGH] CWE-77 CVE-2019-6622: On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4, an
On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.5, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4, an undisclosed iControl REST worker is vulnerable to command injection by an administrator or resource administrator user. This attack is only exploitable on multi-bladed systems.
nvd
CVE-2023-22323P3HIGHCVSS 7.5≥ 17.0.0, < 17.0.0.2≥ 16.1.0, < 16.1.3.3+3 more2023-02-01
CVE-2023-22323 [HIGH] CWE-770 CVE-2023-22323: In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x be
In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when OCSP authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (E
nvd
CVE-2020-5873P3HIGHCVSS 7.2≥ 17.1.0, < 17.1.1≥ 16.1.0, < 16.1.4+1 more2020-04-30
CVE-2020-5873 [HIGH] CWE-78 CVE-2020-5873: On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG-
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG-IQ 5.2.0-7.1.0, a user associated with the Resource Administrator role who has access to the secure copy (scp) utility but does not have access to Advanced Shell (bash) can execute arbitrary commands using a maliciously crafted scp request.
nvd
CVE-2025-48008P3HIGHCVSS 7.5≥ 17.1.0, < 17.1.2.2≥ 16.1.0, < 16.1.6+1 more2025-10-15
CVE-2025-48008 [HIGH] CWE-416 CVE-2025-48008: When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed
When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40067P3HIGHCVSS 7.5≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-40067 [HIGH] CWE-120 CVE-2026-40067: When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the
When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-40060P3HIGHCVSS 7.5≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-40060 [HIGH] CWE-252 CVE-2026-40060: When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed req
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-54854P3HIGHCVSS 7.5≥ 17.5.0, < 17.5.1.3≥ 17.1.0, < 17.1.3+2 more2025-10-15
CVE-2025-54854 [HIGH] CWE-125 CVE-2025-54854: When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtu
When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2025-61960P3HIGHCVSS 7.5≥ 17.5.0, < 17.5.1.3≥ 17.1.0, < 17.1.3+1 more2025-10-15
CVE-2025-61960 [HIGH] CWE-476 CVE-2025-61960: When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed tr
When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-41956P3HIGHCVSS 7.5≥ 17.5.0, < 17.5.1.4≥ 17.1.0, < 17.1.3.1+1 more2026-05-13
CVE-2026-41956 [HIGH] CWE-121 CVE-2026-41956: When a classification profile is configured on a UDP virtual server, undisclosed requests can cause
When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2026-42409P3HIGHCVSS 7.5≥ 21.0.0, < 21.0.0.1≥ 17.5.0, < 17.5.1.4+2 more2026-05-13
CVE-2026-42409 [HIGH] CWE-476 CVE-2026-42409: When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are confi
When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
nvd
CVE-2022-35735P3HIGHCVSS 7.2≥ 13.1.0, < 13.1.x*≥ 14.1.x, < 14.1.5.1+2 more2022-08-04
CVE-2022-35735 [HIGH] CWE-74 CVE-2022-35735: In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all v
In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, an authenticated attacker with Resource Administrator or Manager privileges can create or modify existing monitor objects in the Configuration utility in an undisclosed manner leading to a privilege escalation. Note: Software versions
nvd
CVE-2023-42768P3HIGHCVSS 7.2≥ 16.1.0, < 16.1.4≥ 15.1.0, < 15.1.9+2 more2023-10-10
CVE-2023-42768 [HIGH] CWE-613 CVE-2023-42768: When a non-admin user has been assigned an administrator role via an iControl REST PUT request and
When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP non-admin user can still have access to iControl REST admin resource. Note: Software versions which have reached End of Technical Suppo
nvd
CVE-2022-34862P3HIGHCVSS 7.5≥ 13.1.0, < 13.1.x*≥ 14.1.x, < 14.1.5+2 more2022-08-04
CVE-2022-34862 [HIGH] CWE-835 CVE-2022-34862: In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all ver
In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when an LTM virtual server is configured to perform normalization, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not
nvd
CVE-2019-6685P3HIGHCVSS 7.8v15.0.0-15.0.1.1v14.1.0-14.1.2.2+4 more2019-12-23
CVE-2019-6685 [HIGH] CWE-269 CVE-2019-6685: On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5,
On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, users with access to edit iRules are able to create iRules which can lead to an elevation of privilege, configuration modification, and arbitrary system command execution.
nvd
CVE-2026-41217P3HIGHCVSS 7.9≥ 21.0.0, < 21.0.0.2≥ 17.5.0, < 17.5.1.6+2 more2026-05-13
CVE-2026-41217 [HIGH] CWE-732 CVE-2026-41217: A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenti
A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.
Note: Software versio
nvd