Skip to content
VulniPulse

F5 BIG-IP Vulnerabilities & Security Advisories

306 advisories tracked · F5 SIRT (f5sirt@f5.com CNA) via NVD · 7 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published F5 advisory that VulniPulse classified as BIG-IP, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 14 critical, 191 high, 94 medium, 8 low.

Android app · Google Play

Monitor F5 CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

F5 SIRT (f5sirt@f5.com CNA) via NVD

F5 is its own CVE Numbering Authority. VulniPulse ingests F5's CVEs from the NVD CNA feed (f5sirt@f5.com), each linking to its my.f5.com / support.f5.com security article. Covers BIG-IP (LTM, ASM/Advanced WAF, APM, AFM), BIG-IP Next, BIG-IQ, NGINX / NGINX Plus, F5OS and Distributed Cloud — internet-facing application-delivery and security appliances that are repeatedly mass-exploited (e.g. the CVE-2023-46747 RCE), so a patch-now enterprise audience.

Latest F5 BIG-IP advisories

High8.7F5

High [CVE-2025-59481] vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may

A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource administrator role to execute arbitrary system commands with higher privileges. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-59481
BIG-IP
Oct 15, 2025
High7.5F5

High [CVE-2025-59478] When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests

When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-59478
BIG-IP
Oct 15, 2025
High7.5F5

High [CVE-2025-58096] When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undisclosed…

When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58096
BIG-IP
Oct 15, 2025
High7.5F5

High [CVE-2025-55669] When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server…

When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-55669
BIG-IP
Oct 15, 2025
High7.5F5

High [CVE-2025-55036] When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled…

When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic may cause memory corruption. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-55036
BIG-IP
Oct 15, 2025
High7.5F5

High [CVE-2025-54858] When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON…

When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-54858
BIG-IP
Oct 15, 2025
High7.5F5

High [CVE-2025-54854] When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic

When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-54854
BIG-IP
Oct 15, 2025
High7.5F5

High [CVE-2025-53856] BIG-IP: When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the…

When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. To determine which BIG-IP platforms have an ePVA chip refer to K12837: Overview of the ePVA feature. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-53856
BIG-IP
Oct 15, 2025
High7.5F5

High [CVE-2025-41430] When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-41430
BIG-IP
Oct 15, 2025
Medium6.1F5

Medium [CVE-2025-61933] reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61933
BIG-IP
Oct 15, 2025
Medium6.1F5

Medium [CVE-2025-59269] stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-59269
BIG-IP
Oct 15, 2025
Medium5.3F5

Medium [CVE-2025-59268] On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated…

On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated remote attacker through the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-59268
BIG-IP
Oct 15, 2025
Medium5.3F5

Medium [CVE-2025-58474] When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or

When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58474
BIG-IPNGINX
Oct 15, 2025
Medium5.3F5

Medium [CVE-2025-58424] On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols

On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity protection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58424
BIG-IP
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-55670] On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls

On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-55670
BIG-IPBIG-IP Next
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-47148] When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity…

When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-47148
BIG-IP
Oct 15, 2025
High7.5F5

High [CVE-2025-52585] When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous…

When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-52585
BIG-IP
Aug 13, 2025
High7.5F5

High [CVE-2025-46405] When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic

When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-46405
BIG-IP
Aug 13, 2025
High7.5F5

High [CVE-2025-41431] BIG-IP: When connection mirroring is configured on a virtual server, undisclosed requests

When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in the standby BIG-IP systems in a traffic group. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-41431
BIG-IP
May 7, 2025
High7.5F5

High [CVE-2025-36525] When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate

When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-36525
BIG-IP
May 7, 2025

← All F5 advisories