LIVE · cybersecurity feed
Live wire
vendor

F5

44 CVEs published in the last four months. Exploited flaws first.

Critical1
High41
Medium1
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-412259.1criticalbig-ip access policy managerA vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manage115d ago
CVE-2026-419578.8highbig-ip access policy managerAn authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ C115d ago
CVE-2026-326738.7highbig-ip access policy managerA vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Admi115d ago
CVE-2026-341768.7highbig-ip access policy managerWhen running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed i115d ago
CVE-2026-429308.7highbig-ip access policy managerWhen running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass 115d ago
CVE-2026-419538.7highbig-ip access policy managerA vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resou115d ago
CVE-2026-406988.7highbig-ip access policy managerA vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at leas115d ago
CVE-2026-429248.7highbig-ip access policy managerAn authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration obje115d ago
CVE-2026-326438.7highbig-ip access policy managerA vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at leas115d ago
CVE-2026-406318.7highbig-ip access policy managerAn authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects t115d ago
CVE-2026-400618.7highbig-ip domain name systemWhen BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh115d ago
CVE-2026-424068.7highbig-ip access policy managerA vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at leas115d ago
CVE-2026-557238.3highnginx ingress controllerWhen NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an inj52d ago
CVE-2026-600058.2highnginx gateway fabricNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module.52d ago
CVE-2026-276548.2highnginx plusNGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attack165d ago
CVE-2026-425308.1highnginx gateway fabricNGINX Open Source has a vulnerability in the ngx_http_v3_module module.80d ago
CVE-2026-429458.1highdosNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module.115d ago
CVE-2026-87118.1highnjsNGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-contr109d ago
CVE-2026-92568.1highnginx open sourceNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module.106d ago
CVE-2026-113118.1highnginx gateway fabricWhen NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the80d ago
CVE-2026-420558.1highdosNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module mod80d ago
CVE-2026-209168.1highbig-iq centralized managementAn authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclose115d ago
CVE-2026-501078.1highnginx gateway fabricWhen NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulner80d ago
CVE-2026-425338.1highnginx gateway fabricA vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string e52d ago
CVE-2026-412177.9highbig-ip access policy managerA vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker115d ago
CVE-2026-326477.8highnginx plusNGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an atta165d ago
CVE-2026-277847.8highnginx open sourceThe 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might 165d ago
CVE-2026-412187.5highbig-ip access policy managerWhen BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, C115d ago
CVE-2026-429207.5highbig-ip access policy managerWhen a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traf115d ago
CVE-2026-400607.5highbig-ip application security managerWhen a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can caus115d ago
CVE-2026-597627.5highbig-ip next cloud-native network functionsWhen an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory res52d ago
CVE-2026-394557.5highbig-ip access policy managerWhen the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentica115d ago
CVE-2026-394587.5highbig-ip access policy managerWhen a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanc115d ago
CVE-2026-412277.5highbig-ip advanced web application firewallOn an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase 115d ago
CVE-2026-400677.5highbig-ip access policy managerWhen a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process 115d ago
CVE-2026-406187.5highbig-ip access policy managerWhen an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Tec115d ago
CVE-2026-406297.5highbig-ip access policy managerWhen SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop pro115d ago
CVE-2026-276517.5highnginx open sourceWhen the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can 165d ago
CVE-2026-424097.5highbig-ip next cloud-native network functionsWhen an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a vir115d ago
CVE-2026-404237.5highbig-ip access policy managerWhen a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microke115d ago
CVE-2026-419567.5highbig-ip access policy managerWhen a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Ma115d ago
CVE-2026-394597.2highbig-ip access policy managerA vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacke115d ago
CVE-2026-287555.4mediumnginx plusNGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper hand165d ago
CVE-2026-287533.7lownginx plusNGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handl165d ago

Filter the full tracker by F5