Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.1
CVE-2026-41225
A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration obj…
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.9
CVE-2026-41217
A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or adm…
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.5
CVE-2026-41218
When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the ur…
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.5
CVE-2026-41227
On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the T…
Big Ip Advanced Web Application Firewall
after 17.5.1
MEDIUM 6.5
CVE-2026-41219
An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a…
Big Ip Access Policy Manager
after 17.5.1
MEDIUM 5.4
CVE-2026-40703
A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility. Note: Software versions which have re…
Big Ip Access Policy Manager
after 17.5.1
HIGH 8.7
CVE-2026-40631
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in p…
Big Ip Access Policy Manager
after 17.5.1
HIGH 8.7
CVE-2026-40698
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role c…
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.5
CVE-2026-40618
When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware…
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.5
CVE-2026-40629
When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections. No…
Big Ip Access Policy Manager
after 17.5.1
MEDIUM 6.5
CVE-2026-40699
A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticated attacker to access to undi…
Big Ip Access Policy Manager
after 17.5.1
HIGH 8.7
CVE-2026-40061
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authent…
Big Ip Domain Name System
after 17.5.1
HIGH 7.5
CVE-2026-40060
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.
…
Big Ip Application Security Manager
after 17.5.1
HIGH 7.5
CVE-2026-40067
When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.
Note: Software vers…
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.5
CVE-2026-40423
When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: So…
Big Ip Access Policy Manager
after 17.5.1
MEDIUM 6.5
CVE-2026-40460
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing …
Dos
after 5.12.1
MEDIUM 6.5
CVE-2026-40462
Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated att…
Big Ip Access Policy Manager
after 17.5.1
MEDIUM 5.3
CVE-2026-40435
When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses. Note: Softwa…
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.5
CVE-2026-39455
When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause…
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.5
CVE-2026-39458
When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel …
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.2
CVE-2026-39459
A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role ca…
Big Ip Access Policy Manager
after 17.5.1
MEDIUM 6.5
CVE-2026-35062
An authenticated iControl SOAP user may be able to obtain information of other accounts.
Note: Software versions which have reached End of Technica…
Big Ip Access Policy Manager
after 17.5.1
HIGH 8.7
CVE-2026-32643
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can …
Big Ip Access Policy Manager
after 17.5.1
HIGH 8.7
CVE-2026-32673
A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to …
Big Ip Access Policy Manager
after 17.5.1
HIGH 8.7
CVE-2026-34176
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful…
Big Ip Access Policy Manager
after 17.5.1
MEDIUM 5.3
CVE-2026-34019
When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Manage…
Big Ip Access Policy Manager
after 17.1.2
HIGH 8.1
CVE-2026-20916
An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG…
Big Iq Centralized Management
Mitigation only
MEDIUM 6.8
CVE-2026-24464
When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated a…
Big Ip Access Policy Manager
after 17.5.1
HIGH 7.8
CVE-2026-32647
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read …
Nginx Plus
1.28.3 / 1.29.7+
HIGH 8.2
CVE-2026-27654EPSS 22%
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to …
Nginx Plus
1.28.3 / 1.29.7+