F5 BIG-IP Next Vulnerabilities & Security Advisories
13 advisories tracked · F5 SIRT (f5sirt@f5.com CNA) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published F5 advisory that VulniPulse classified as BIG-IP Next, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 7 high, 6 medium.
Android app · Google Play
Monitor F5 CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
F5 SIRT (f5sirt@f5.com CNA) via NVD
F5 is its own CVE Numbering Authority. VulniPulse ingests F5's CVEs from the NVD CNA feed (f5sirt@f5.com), each linking to its my.f5.com / support.f5.com security article. Covers BIG-IP (LTM, ASM/Advanced WAF, APM, AFM), BIG-IP Next, BIG-IQ, NGINX / NGINX Plus, F5OS and Distributed Cloud — internet-facing application-delivery and security appliances that are repeatedly mass-exploited (e.g. the CVE-2023-46747 RCE), so a patch-now enterprise audience.
Latest F5 BIG-IP Next advisories
High [CVE-2026-59762] BIG-IP: When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected products named by the advisory: BIG-IP Next for Kubernetes; BIG-IP Next SPK; BIG-IP Next CNF.
High [CVE-2025-59781] When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries
When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Medium [CVE-2025-55670] On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls
On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Medium [CVE-2025-24319] When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API
When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes service to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Medium [CVE-2025-23413] When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager
When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Medium [CVE-2024-41719] When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged…
When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Medium [CVE-2024-37028] BIG-IP Next: BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.
BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
High [CVE-2024-32049] BIG-IP Next Central Manager (CM) may
BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
High [CVE-2024-26026] BIG-IP Next: SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).
An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
High [CVE-2024-21793] BIG-IP Next: OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).
An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Medium [CVE-2024-33612] improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may
An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
High [CVE-2024-23314] When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses
When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
High [CVE-2024-23306] BIG-IP Next: vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files.
A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated