Skip to content
VulniPulse

F5 Security Advisories & CVEs

153 advisories tracked · F5 SIRT (f5sirt@f5.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor F5 CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your F5 device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in F5's recent advisories.

Official source

F5 SIRT (f5sirt@f5.com CNA) via NVD

F5 is its own CVE Numbering Authority. VulniPulse ingests F5's CVEs from the NVD CNA feed (f5sirt@f5.com), each linking to its my.f5.com / support.f5.com security article. Covers BIG-IP (LTM, ASM/Advanced WAF, APM, AFM), BIG-IP Next, BIG-IQ, NGINX / NGINX Plus, F5OS and Distributed Cloud — internet-facing application-delivery and security appliances that are repeatedly mass-exploited (e.g. the CVE-2023-46747 RCE), so a patch-now enterprise audience.

Latest F5 advisories

Medium5.9F5

Medium [CVE-2026-22548] When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions…

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-22548
BIG-IP
Feb 4, 2026
Medium5.9F5

Medium [CVE-2026-1642] vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers

A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-1642
NGINX
Feb 4, 2026
Medium6.1F5

Medium [CVE-2025-61933] reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61933
BIG-IP
Oct 15, 2025
Medium4.1F5

Medium [CVE-2025-53860] vulnerability exists in F5OS-A software

A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries systems. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-53860
F5OS / Distributed Cloud
Oct 15, 2025
Medium5.7F5

Medium [CVE-2025-60015] F5OS: out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption.

An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-60015
F5OS / Distributed Cloud
Oct 15, 2025
Medium4.6F5

Medium [CVE-2025-60013] When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special…

When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) may fail to initialize. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-60013
Unclassified
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-59483] validation vulnerability exists in an undisclosed URL in the Configuration utility.

A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-59483
Unclassified
Oct 15, 2025
Medium6.1F5

Medium [CVE-2025-59269] stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-59269
BIG-IP
Oct 15, 2025
Medium5.3F5

Medium [CVE-2025-59268] On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated…

On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated remote attacker through the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-59268
BIG-IP
Oct 15, 2025
Medium5.3F5

Medium [CVE-2025-58474] When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or

When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58474
BIG-IPNGINX
Oct 15, 2025
Medium5.3F5

Medium [CVE-2025-58424] On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols

On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity protection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58424
BIG-IP
Oct 15, 2025
Medium5.9F5

Medium [CVE-2025-58153] Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-Speed…

Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-Speed Bridge (HSB) may experience a lockup of the HSB. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58153
Unclassified
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-55670] On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls

On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-55670
BIG-IPBIG-IP Next
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-54805] When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process

When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-54805
Unclassified
Oct 15, 2025
Medium4.9F5

Medium [CVE-2025-54755] directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access files

A directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access files which are not limited to the intended files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-54755
Unclassified
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-47150] When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests

When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-47150
F5OS / Distributed Cloud
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-47148] When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity…

When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-47148
BIG-IP
Oct 15, 2025
Medium5.3F5

Medium [CVE-2025-54500] HTTP/2 implementation flaw

An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-54500
Unclassified
Aug 13, 2025
Medium6.0F5

Medium [CVE-2025-43878] F5OS: When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role

When running in Appliance mode, an authenticated attacker assigned the Administrator or Resource Administrator role may be able to bypass Appliance mode restrictions utilizing system diagnostics tcpdump command utility on a F5OS-C/A system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-43878
F5OS / Distributed Cloud
May 7, 2025
Medium5.3F5

Medium [CVE-2025-1695] In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can

In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization. This vulnerability allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS). There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-1695
NGINX
Mar 4, 2025

← All vendors