imPC@ndo IT

F5 vulnerabilities

1037 CVE

CVE-2021-23023
High 7.8

On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evalu…

f5 big-ip_access_policy_manager
0.00EPSS
CVE-2019-19151
Medium 5.5

On BIG-IP versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IQ versions 7.0.0, 6.0.0-6.1.0, and 5.0.0-5.4.0, iWorkflow version 2.3.0, and Enterprise Manager version 3.1.1, authenticated users granted TMOS Shell (…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · and 12 more
0.00EPSS
CVE-2020-5896
High 7.8

On versions 7.1.5-7.1.9, the BIG-IP Edge Client's Windows Installer Service's temporary folder has weak file and folder permissions.

f5 big-ip_access_policy_manager · f5 big-ip_access_policy_manager_client
0.00EPSS
CVE-2026-41954
Medium 4.9

Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information.  Note: Software v…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 18 more
0.00EPSS
CVE-2026-55723
High 8.3

When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the gen…

f5 nginx_ingress_controller
0.00EPSS
CVE-2026-34019
Medium 5.3

When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets and cause the configured routing protocol to fail over.  …

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 17 more
0.00EPSS
CVE-2026-32682
Medium 6.5

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPCRoute configurations co…

f5 nginx_gateway_fabric
0.00EPSS
CVE-2026-42063
Medium 4.9

A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator role can download sensitive files.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 17 more
0.00EPSS
CVE-2026-42919
Medium 6.7

A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary.  Note: Software versions which have reached En…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 17 more
0.00EPSS
CVE-2022-28714
High 7.3

On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, a …

f5 big-ip_access_policy_manager · f5 big-ip_access_policy_manager_client
0.00EPSS
CVE-2022-38890
Medium 5.5

Nginx NJS v0.7.7 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h

f5 njs
0.00EPSS
CVE-2019-6668
Medium 5.5

The BIG-IP APM Edge Client for macOS bundled with BIG-IP APM 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.5, and 11.5.1-11.6.5 may allow unprivileged users to access files owned by root.

f5 big-ip_access_policy_manager
0.00EPSS
CVE-2026-52865
Medium 6.5

When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: Th…

f5 nginx_ingress_controller
0.00EPSS
CVE-2023-24461
High 7.4

An improper certificate validation vulnerability exists in the BIG-IP Edge Client for Windows and macOS and may allow an attacker to impersonate a BIG-IP APM system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated…

f5 big-ip_access_policy_manager
0.00EPSS
CVE-2025-55670
Medium 6.5

On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not eva…

f5 big-ip_next_cloud-native_network_functions · f5 big-ip_next_for_kubernetes · f5 big-ip_next_service_proxy_for_kubernetes
0.00EPSS
CVE-2025-54805
Medium 6.5

When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization.  Note: Software versions which have reached End o…

f5 big-ip_next_cloud-native_network_functions · f5 big-ip_next_for_kubernetes · f5 big-ip_next_service_proxy_for_kubernetes
0.00EPSS
CVE-2021-22980
High 7.8

In Edge Client version 7.2.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, and 7.1.x-7.1.8.x before 7.1.8.5, an untrusted search path vulnerability in the BIG-IP APM Client Troubleshooting Utility (CTU) for Windows could allow an attacker to load a malicious DLL lib…

f5 access_policy_manager_clients · f5 big-ip_access_policy_manager
0.00EPSS
CVE-2026-41219
Medium 6.5

An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 18 more
0.00EPSS
CVE-2026-40699
Medium 6.5

A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticated attacker to access to undisclosed sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are …

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 17 more
0.00EPSS
CVE-2021-23012
High 8.2

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow users granted either "Resource Administrator" or "Administrat…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 10 more
0.00EPSS
CVE-2026-41225
Critical 9.1

A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.  Note: Software versions which have reached End of Technical Suppo…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 17 more
0.00EPSS
CVE-2024-27202
Medium 4.7

A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 17 more
0.00EPSS
CVE-2026-60065
Low 3.7

When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the…

f5 nginx_gateway_fabric · f5 nginx_ingress_controller · f5 nginx_plus · f5 waf
0.00EPSS
CVE-2026-28753
Low 3.7

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, lea…

f5 nginx_open_source · f5 nginx_plus
0.00EPSS
CVE-2026-42920
High 7.5

When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) a…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · and 17 more
0.00EPSS