Skip to content
VulniPulse

F5 Security Advisories & CVEs

453 advisories tracked · F5 SIRT (f5sirt@f5.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor F5 CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your F5 device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in F5's recent advisories.

Official source

F5 SIRT (f5sirt@f5.com CNA) via NVD

F5 is its own CVE Numbering Authority. VulniPulse ingests F5's CVEs from the NVD CNA feed (f5sirt@f5.com), each linking to its my.f5.com / support.f5.com security article. Covers BIG-IP (LTM, ASM/Advanced WAF, APM, AFM), BIG-IP Next, BIG-IQ, NGINX / NGINX Plus, F5OS and Distributed Cloud — internet-facing application-delivery and security appliances that are repeatedly mass-exploited (e.g. the CVE-2023-46747 RCE), so a patch-now enterprise audience.

Latest F5 advisories

High7.5F5

High [CVE-2025-54858] When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON…

When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-54858
BIG-IP
Oct 15, 2025
High7.5F5

High [CVE-2025-54854] When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic

When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-54854
BIG-IP
Oct 15, 2025
High7.5F5

High [CVE-2025-54479] When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests

When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-54479
Unclassified
Oct 15, 2025
High8.7F5

High [CVE-2025-53868] When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP

When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to bypass Appliance mode restrictions using undisclosed commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-53868
Unclassified
Oct 15, 2025
High7.5F5

High [CVE-2025-53856] BIG-IP: When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the…

When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. To determine which BIG-IP platforms have an ePVA chip refer to K12837: Overview of the ePVA feature. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-53856
BIG-IP
Oct 15, 2025
High7.5F5

High [CVE-2025-53474] When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic

When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-53474
Unclassified
Oct 15, 2025
High7.5F5

High [CVE-2025-48008] When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with…

When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-48008
Unclassified
Oct 15, 2025
High7.5F5

High [CVE-2025-46706] When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests

When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-46706
Unclassified
Oct 15, 2025
High7.5F5

High [CVE-2025-41430] When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-41430
BIG-IP
Oct 15, 2025
Medium6.1F5

Medium [CVE-2025-61933] reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61933
BIG-IP
Oct 15, 2025
Medium4.1F5

Medium [CVE-2025-53860] vulnerability exists in F5OS-A software

A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries systems. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-53860
F5OS / Distributed Cloud
Oct 15, 2025
Medium5.7F5

Medium [CVE-2025-60015] F5OS: out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption.

An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-60015
F5OS / Distributed Cloud
Oct 15, 2025
Medium4.6F5

Medium [CVE-2025-60013] When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special…

When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) may fail to initialize. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-60013
Unclassified
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-59483] validation vulnerability exists in an undisclosed URL in the Configuration utility.

A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-59483
Unclassified
Oct 15, 2025
Medium6.1F5

Medium [CVE-2025-59269] stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-59269
BIG-IP
Oct 15, 2025
Medium5.3F5

Medium [CVE-2025-59268] On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated…

On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated remote attacker through the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-59268
BIG-IP
Oct 15, 2025
Medium5.3F5

Medium [CVE-2025-58474] When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or

When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58474
BIG-IPNGINX
Oct 15, 2025
Medium5.3F5

Medium [CVE-2025-58424] On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols

On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity protection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58424
BIG-IP
Oct 15, 2025
Medium5.9F5

Medium [CVE-2025-58153] Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-Speed…

Under undisclosed traffic conditions along with conditions beyond the attacker's control, hardware systems with a High-Speed Bridge (HSB) may experience a lockup of the HSB. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58153
Unclassified
Oct 15, 2025
Medium6.5F5

Medium [CVE-2025-55670] On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls

On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-55670
BIG-IPBIG-IP Next
Oct 15, 2025

← All vendors