Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Access Policy Manager CRITICAL 9.1
CVE-2026-41225

A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration obj…

Fix: after 17.5.1
Fix from $2,300 2026-05-13
Big Ip Access Policy Manager HIGH 7.9
CVE-2026-41217

A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or adm…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2026-41218

When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the ur…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2026-41227

On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the T…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2026-41219

An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager MEDIUM 5.4
CVE-2026-40703

A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility.  Note: Software versions which have re…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager HIGH 8.7
CVE-2026-40631

An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in p…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 8.7
CVE-2026-40698

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role c…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2026-40618

When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2026-40629

When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  No…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2026-40699

A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticated attacker to access to undi…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Big Ip Domain Name System HIGH 8.7
CVE-2026-40061

When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authent…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Application Security Manager HIGH 7.5
CVE-2026-40060

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  …

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2026-40067

When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.  Note: Software vers…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2026-40423

When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: So…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Dos MEDIUM 6.5
CVE-2026-40460

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing …

Fix: after 5.12.1
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2026-40462

Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated att…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2026-40435

When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses.  Note: Softwa…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2026-39455

When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2026-39458

When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel …

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 7.2
CVE-2026-39459

A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role ca…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2026-35062

An authenticated iControl SOAP user may be able to obtain information of other accounts.  Note: Software versions which have reached End of Technica…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager HIGH 8.7
CVE-2026-32643

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can …

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 8.7
CVE-2026-32673

A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to …

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 8.7
CVE-2026-34176

When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2026-34019

When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Manage…

Fix: after 17.1.2
Fix from $1,600 2026-05-13
Big Iq Centralized Management HIGH 8.1
CVE-2026-20916

An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG…

Mitigation only
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager MEDIUM 6.8
CVE-2026-24464

When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated a…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Nginx Plus HIGH 7.8
CVE-2026-32647

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read …

Fix: 1.28.3 / 1.29.7+
Fix from $1,950 2026-03-24
Nginx Plus HIGH 8.2
CVE-2026-27654EPSS 22%

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to …

Fix: 1.28.3 / 1.29.7+
Fix from $1,950 2026-03-24