Skip to content
VulniPulse

F5 Security Advisories & CVEs

8 advisories tracked · F5 SIRT (f5sirt@f5.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor F5 CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your F5 device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in F5's recent advisories.

Official source

F5 SIRT (f5sirt@f5.com CNA) via NVD

F5 is its own CVE Numbering Authority. VulniPulse ingests F5's CVEs from the NVD CNA feed (f5sirt@f5.com), each linking to its my.f5.com / support.f5.com security article. Covers BIG-IP (LTM, ASM/Advanced WAF, APM, AFM), BIG-IP Next, BIG-IQ, NGINX / NGINX Plus, F5OS and Distributed Cloud — internet-facing application-delivery and security appliances that are repeatedly mass-exploited (e.g. the CVE-2023-46747 RCE), so a patch-now enterprise audience.

Latest F5 advisories

Low3.1F5

Low [CVE-2026-20732] vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-20732
BIG-IP
Feb 4, 2026
Low3.3F5

Low [CVE-2026-20730] vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may

A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2026-20730
BIG-IP
Feb 4, 2026
Low3.7F5

Low [CVE-2025-53859] NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the authentication server. This issue happens during the NGINX SMTP authentication process and requires the attacker to make preparations against the target system to extract the leaked data. The issue affects NGINX only if (1) it is built with the ngx_mail_smtp_module, (2) the smtp_auth directive is configured with method "none," and (3) the authentication server returns the "Auth-Wait" response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-53859
NGINX
Aug 13, 2025
Low3.1F5

Low [CVE-2025-23415] insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may

An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may allow an attacker to bypass endpoint inspection checks for VPN connection initiated thru BIG-IP APM browser network access VPN client for Windows, macOS and Linux. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-23415
BIG-IP
Feb 5, 2025
Low3.8F5

Low [CVE-2024-23603] BIG-IP: An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.

An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-23603
BIG-IP
Feb 14, 2024
Low3.7F5

Low [CVE-2022-41983] On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all…

On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, while Intel QAT (QuickAssist Technology) and the AES-GCM/CCM cipher is in use, undisclosed conditions can cause BIG-IP to send data unencrypted even with an SSL Profile applied.

CVE-2022-41983
BIG-IP
Oct 19, 2022
Low3.7F5

Low [CVE-2022-33968] In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all…

In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, when an LTM monitor or APM SSO is configured on a virtual server, and NTLM challenge-response is in use, undisclosed traffic can cause a buffer over-read. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2022-33968
BIG-IP
Aug 4, 2022
Low3.1F5

Low [CVE-2022-1389] On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site request…

On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site request forgery (CSRF) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This vulnerability allows an attacker to run a limited set of commands: ping, traceroute, and WOM diagnostics. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2022-1389
BIG-IP
May 5, 2022

← All vendors