Skip to content
VulniPulse

F5 BIG-IP Vulnerabilities & Security Advisories

306 advisories tracked · F5 SIRT (f5sirt@f5.com CNA) via NVD · 7 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published F5 advisory that VulniPulse classified as BIG-IP, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 14 critical, 191 high, 94 medium, 8 low.

Android app · Google Play

Monitor F5 CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

F5 SIRT (f5sirt@f5.com CNA) via NVD

F5 is its own CVE Numbering Authority. VulniPulse ingests F5's CVEs from the NVD CNA feed (f5sirt@f5.com), each linking to its my.f5.com / support.f5.com security article. Covers BIG-IP (LTM, ASM/Advanced WAF, APM, AFM), BIG-IP Next, BIG-IQ, NGINX / NGINX Plus, F5OS and Distributed Cloud — internet-facing application-delivery and security appliances that are repeatedly mass-exploited (e.g. the CVE-2023-46747 RCE), so a patch-now enterprise audience.

Latest F5 BIG-IP advisories

Medium6.9F5

Medium [CVE-2026-42780] directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files

A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-42780
BIG-IP
May 13, 2026
Medium6.7F5

Medium [CVE-2026-42408] When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information

When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-42408
BIG-IP
May 13, 2026
Medium5.3F5

Medium [CVE-2026-42058] authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local user account names

An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-42058
BIG-IP
May 13, 2026
Medium5.3F5

Medium [CVE-2026-40703] cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility

A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-40703
BIG-IP
May 13, 2026
Medium6.7F5

Medium [CVE-2026-28758] When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the…

When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is also logged in the audit log. This may allow a highly privileged, authenticated attacker with access to the audit log to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2026-28758
BIG-IP
May 13, 2026
Medium4.9F5

Medium [CVE-2026-22549] vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets

A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-22549
BIG-IP
Feb 4, 2026
Medium5.9F5

Medium [CVE-2026-22548] When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions…

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-22548
BIG-IP
Feb 4, 2026
Medium6.1F5

Medium [CVE-2025-61933] reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61933
BIG-IP
Oct 15, 2025
Medium6.1F5

Medium [CVE-2025-59269] stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-59269
BIG-IP
Oct 15, 2025
Medium5.3F5

Medium [CVE-2025-59268] On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated…

On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated remote attacker through the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-59268
BIG-IP
Oct 15, 2025
Medium5.3F5

Medium [CVE-2025-58474] When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or

When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58474
BIG-IPNGINX
Oct 15, 2025
Medium5.3F5

Medium [CVE-2025-58424] On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols

On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity protection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58424
BIG-IP
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-55670] On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls

On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-55670
BIG-IPBIG-IP Next
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-47148] When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity…

When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-47148
BIG-IP
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-24319] When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API

When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes service to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-24319
BIG-IPBIG-IP Next
Feb 5, 2025
Medium4.4F5

Medium [CVE-2025-23413] When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager

When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-23413
BIG-IPBIG-IP Next
Feb 5, 2025
Medium4.3F5

Medium [CVE-2024-41723] BIG-IP: Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names.

Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-41723
BIG-IP
Aug 14, 2024
Medium4.2F5

Medium [CVE-2024-41719] When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged…

When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-41719
BIG-IPBIG-IP Next
Aug 14, 2024
Medium5.3F5

Medium [CVE-2024-37028] BIG-IP Next: BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.

BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-37028
BIG-IPBIG-IP Next
Aug 14, 2024
Medium6.8F5

Medium [CVE-2024-33612] improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may

An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-33612
BIG-IPBIG-IP Next
May 8, 2024

← All F5 advisories