Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

F5

904 known vulnerabilities

1
CRITICAL
41
HIGH
32
MEDIUM
4
LOW

Top Products

big-ip advanced web application firewall 42 big-ip application security manager 42 big-ip access policy manager 41 big-ip domain name system 41 big-ip container ingress services 40 big-ip ddos hybrid defender 40 big-ip advanced firewall manager 39 big-ip analytics 39 big-ip application acceleration manager 39 big-ip application visibility and reporting 39
78 CVEs · Page 2/2
6.5
CVE-2026-40460

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof thei

5.3
CVE-2026-40435

When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blo

7.5
CVE-2026-40423

When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (

7.5
CVE-2026-40067

When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to ter

8.7
CVE-2026-40061

When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) comm

7.5
CVE-2026-40060

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the

7.2
CVE-2026-39459

A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with

7.5
CVE-2026-39458

When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WA

7.5
CVE-2026-39455

When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication,

6.5
CVE-2026-35062

An authenticated iControl SOAP user may be able to obtain information of other accounts.  Note: Software versions which

8.7
CVE-2026-34176

When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iContro

5.3
CVE-2026-34019

When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic

8.7
CVE-2026-32673

A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administra

8.7
CVE-2026-32643

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the

4.4
CVE-2026-28758

When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return t

6.8
CVE-2026-24464

When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that

8.1
CVE-2026-20916

An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iCon

7.8
CVE-2026-32647

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker t

5.4
CVE-2026-28755

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling o

3.7
CVE-2026-28753

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of

7.8
CVE-2026-27784

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow

8.2
CVE-2026-27654

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to

7.5
CVE-2026-27651

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause

4.9
CVE-2026-22549

A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secr

5.9
CVE-2026-22548

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with con

3.1
CVE-2026-20732

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error mes

3.3
CVE-2026-20730

A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access

5.9
CVE-2026-1642

A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) s

Frequently Asked Questions

How many CVEs affect F5?

F5 has 904 CVE records in our database, including 20 critical and 477 high severity vulnerabilities.

What are the most severe F5 vulnerabilities?

F5 has 20 critical severity (CVSS 9.0+) and 477 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for F5 vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in F5 products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect F5 Vulnerabilities

CyberStrike scans your infrastructure for F5 vulnerabilities and provides real-time remediation guidance.

Get Started