| CVE-2026-41957 | 8.8 | high | f5 / big-ip access policy manager | An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ C | 115d ago |
| CVE-2026-42930 | 8.7 | high | f5 / big-ip access policy manager | When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass | 115d ago |
| CVE-2026-42924 | 8.7 | high | f5 / big-ip access policy manager | An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration obje | 115d ago |
| CVE-2026-42406 | 8.7 | high | f5 / big-ip access policy manager | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at leas | 115d ago |
| CVE-2026-41953 | 8.7 | high | f5 / big-ip access policy manager | A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resou | 115d ago |
| CVE-2026-40698 | 8.7 | high | f5 / big-ip access policy manager | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at leas | 115d ago |
| CVE-2026-40631 | 8.7 | high | f5 / big-ip access policy manager | An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects t | 115d ago |
| CVE-2026-40061 | 8.7 | high | f5 / big-ip domain name system | When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh | 115d ago |
| CVE-2026-34176 | 8.7 | high | f5 / big-ip access policy manager | When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed i | 115d ago |
| CVE-2026-32673 | 8.7 | high | f5 / big-ip access policy manager | A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Admi | 115d ago |
| CVE-2026-32643 | 8.7 | high | f5 / big-ip access policy manager | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at leas | 115d ago |
| CVE-2026-55723 | 8.3 | high | f5 / nginx ingress controller | When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an inj | 52d ago |
| CVE-2026-60005 | 8.2 | high | f5 / nginx gateway fabric | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. | 52d ago |
| CVE-2026-27654 | 8.2 | high | f5 / nginx plus | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attack | 165d ago |
| CVE-2026-42533 | 8.1 | high | f5 / nginx gateway fabric | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string e | 52d ago |
| CVE-2026-50107 | 8.1 | high | f5 / nginx gateway fabric | When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulner | 80d ago |
| CVE-2026-42530 | 8.1 | high | f5 / nginx gateway fabric | NGINX Open Source has a vulnerability in the ngx_http_v3_module module. | 80d ago |
| CVE-2026-42055 | 8.1 | high | f5 / dos | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module mod | 80d ago |
| CVE-2026-11311 | 8.1 | high | f5 / nginx gateway fabric | When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the | 80d ago |
| CVE-2026-9256 | 8.1 | high | f5 / nginx open source | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. | 106d ago |
| CVE-2026-8711 | 8.1 | high | f5 / njs | NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-contr | 109d ago |
| CVE-2026-42945 | 8.1 | high | f5 / dos | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. | 115d ago |
| CVE-2026-20916 | 8.1 | high | f5 / big-iq centralized management | An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclose | 115d ago |
| CVE-2026-41217 | 7.9 | high | f5 / big-ip access policy manager | A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker | 115d ago |
| CVE-2026-32647 | 7.8 | high | f5 / nginx plus | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an atta | 165d ago |
| CVE-2026-27784 | 7.8 | high | f5 / nginx open source | The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might | 165d ago |
| CVE-2026-59762 | 7.5 | high | f5 / big-ip next cloud-native network functions | When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory res | 52d ago |
| CVE-2026-42920 | 7.5 | high | f5 / big-ip access policy manager | When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traf | 115d ago |
| CVE-2026-42409 | 7.5 | high | f5 / big-ip next cloud-native network functions | When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a vir | 115d ago |
| CVE-2026-41956 | 7.5 | high | f5 / big-ip access policy manager | When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Ma | 115d ago |
| CVE-2026-41227 | 7.5 | high | f5 / big-ip advanced web application firewall | On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase | 115d ago |
| CVE-2026-41218 | 7.5 | high | f5 / big-ip access policy manager | When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, C | 115d ago |
| CVE-2026-40629 | 7.5 | high | f5 / big-ip access policy manager | When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop pro | 115d ago |
| CVE-2026-40618 | 7.5 | high | f5 / big-ip access policy manager | When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Tec | 115d ago |
| CVE-2026-40423 | 7.5 | high | f5 / big-ip access policy manager | When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microke | 115d ago |
| CVE-2026-40067 | 7.5 | high | f5 / big-ip access policy manager | When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process | 115d ago |
| CVE-2026-40060 | 7.5 | high | f5 / big-ip application security manager | When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can caus | 115d ago |
| CVE-2026-39458 | 7.5 | high | f5 / big-ip access policy manager | When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanc | 115d ago |
| CVE-2026-39455 | 7.5 | high | f5 / big-ip access policy manager | When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentica | 115d ago |
| CVE-2026-27651 | 7.5 | high | f5 / nginx open source | When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can | 165d ago |
| CVE-2026-39459 | 7.2 | high | f5 / big-ip access policy manager | A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacke | 115d ago |