Skip to content
VulniPulse

F5 Security Advisories & CVEs

273 advisories tracked · F5 SIRT (f5sirt@f5.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor F5 CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your F5 device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in F5's recent advisories.

Official source

F5 SIRT (f5sirt@f5.com CNA) via NVD

F5 is its own CVE Numbering Authority. VulniPulse ingests F5's CVEs from the NVD CNA feed (f5sirt@f5.com), each linking to its my.f5.com / support.f5.com security article. Covers BIG-IP (LTM, ASM/Advanced WAF, APM, AFM), BIG-IP Next, BIG-IQ, NGINX / NGINX Plus, F5OS and Distributed Cloud — internet-facing application-delivery and security appliances that are repeatedly mass-exploited (e.g. the CVE-2023-46747 RCE), so a patch-now enterprise audience.

Latest F5 advisories

High8.5F5

High [CVE-2026-34176] F5: When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST…

When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected product named by the advisory: F5. Affected product named by the advisory: F5.

CVE-2026-34176
Unclassified
May 13, 2026
High8.5F5

High [CVE-2026-32673] vulnerability exists in BIG-IP scripted monitors that may

A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-32673
BIG-IP
May 13, 2026
High8.5F5

High [CVE-2026-32643] vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the…

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-32643
BIG-IPBIG-IQ
May 13, 2026
High7.2F5

High [CVE-2026-20916] BIG-IQ: authenticated iControl REST user with low privileges

An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-20916
BIG-IQ
May 13, 2026
High8.5F5

High [CVE-2026-32647] NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-32647
NGINX
Mar 24, 2026
High7.8F5

High [CVE-2026-27784] NGINX ngx_http_mp4_module vulnerability

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-27784
NGINX
Mar 24, 2026
High8.2F5

High [CVE-2026-27654] NGINX ngx_http_dav_module vulnerability

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-27654
NGINX
Mar 24, 2026
High7.5F5

High [CVE-2026-27651] NGINX ngx_mail_auth_http_module vulnerability

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-27651
NGINX
Mar 24, 2026
High7.5F5

High [CVE-2026-2507] BIG-IP: When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate.

When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-2507
BIG-IP
Feb 18, 2026
High8.3F5

High [CVE-2025-14727] NGINX: vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation.

A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-14727
NGINX
Dec 17, 2025
High7.5F5

High [CVE-2025-61990] When using a multi-bladed platform with more than one blade, undisclosed traffic

When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61990
Unclassified
Oct 15, 2025
High7.5F5

High [CVE-2025-61935] When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests

When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61935
BIG-IP
Oct 15, 2025
High7.5F5

High [CVE-2025-58071] When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate

When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58071
BIG-IP
Oct 15, 2025
High8.8F5

High [CVE-2025-57780] vulnerability exists in F5OS-A and F5OS-C system that may

A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-57780
F5OS / Distributed Cloud
Oct 15, 2025
High7.5F5

High [CVE-2025-61974] When a client SSL profile is configured on a virtual server, undisclosed requests

When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61974
Unclassified
Oct 15, 2025
High7.5F5

High [CVE-2025-61960] When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic

When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61960
BIG-IP
Oct 15, 2025
High8.7F5

High [CVE-2025-61958] BIG-IP: vulnerability exists in the iHealth command that may

A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell. For BIG-IP systems running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61958
BIG-IP
Oct 15, 2025
High8.8F5

High [CVE-2025-61955] vulnerability exists in F5OS-A and F5OS-C systems that may

A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61955
F5OS / Distributed Cloud
Oct 15, 2025
High7.5F5

High [CVE-2025-61951] Undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.

Undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. This issue may occur when a Datagram Transport Layer Security (DTLS) 1.2 virtual server is enabled with a Server SSL profile that is configured with a certificate, key, and the SSL Sign Hash set to ANY, and the backend server is enabled with DTLS 1.2 and client authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61951
Unclassified
Oct 15, 2025
High7.5F5

High [CVE-2025-61938] When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data…

When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process can terminate repeatedly. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61938
BIG-IP
Oct 15, 2025

← All vendors