<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – BIG-IP</title>
  <link>https://cvedaily.com/pages/tags/big-ip.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/big-ip.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – BIG-IP</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-42937 – Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42937</guid>
    <pubDate>Wed, 13 May 2026 16:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42937</strong></p>
  <p>Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view adjacent network information.     Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42930 – When running in Appliance mode, an authenticated attacker assigned the 'Administ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42930</guid>
    <pubDate>Wed, 13 May 2026 16:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42930</strong></p>
  <p>When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42919 – A vulnerability exists in BIG-IP systems that may allow an authenticated attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42919</guid>
    <pubDate>Wed, 13 May 2026 16:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42919</strong></p>
  <p>A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42780 – A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42780</guid>
    <pubDate>Wed, 13 May 2026 16:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42780</strong></p>
  <p>A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42408 – When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Sh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42408</guid>
    <pubDate>Wed, 13 May 2026 16:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42408</strong></p>
  <p>When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a highly privileged authenticated attacker to view sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42406 – A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42406</guid>
    <pubDate>Wed, 13 May 2026 16:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42406</strong></p>
  <p>A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.     Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42058 – An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42058</guid>
    <pubDate>Wed, 13 May 2026 16:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42058</strong></p>
  <p>An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local user account names.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41959 – Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41959</guid>
    <pubDate>Wed, 13 May 2026 16:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41959</strong></p>
  <p>Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view the network status of destination systems.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41957 – An authenticated remote code execution vulnerability through undisclosed vectors...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41957</guid>
    <pubDate>Wed, 13 May 2026 16:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41957</strong></p>
  <p>An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41953 – A vulnerability exists in BIG-IP systems where a highly privileged, authenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41953</guid>
    <pubDate>Wed, 13 May 2026 16:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41953</strong></p>
  <p>A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41219 – An improper sanitization vulnerability exists in the BIG-IP QKView utility that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41219</guid>
    <pubDate>Wed, 13 May 2026 16:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41219</strong></p>
  <p>An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file.     Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41218 – When BIG-IP PEM iRules are configured on a virtual server (iRules using commands...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41218</guid>
    <pubDate>Wed, 13 May 2026 16:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41218</strong></p>
  <p>When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41217 – A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41217</guid>
    <pubDate>Wed, 13 May 2026 16:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41217</strong></p>
  <p>A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.   Note: Software versions which have reached End of Technical Suppor…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40703 – A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40703</guid>
    <pubDate>Wed, 13 May 2026 16:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40703</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40698 – A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40698</guid>
    <pubDate>Wed, 13 May 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40698</strong></p>
  <p>A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40618 – When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40618</guid>
    <pubDate>Wed, 13 May 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40618</strong></p>
  <p>When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.    Note: Software versions which have reached End of Technical Support (EoTS) are not ev…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40067 – When a BIG-IP APM access policy is configured on a virtual server, undisclosed t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40067</guid>
    <pubDate>Wed, 13 May 2026 16:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40067</strong></p>
  <p>When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40061 – When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iContro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40061</guid>
    <pubDate>Wed, 13 May 2026 16:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40061</strong></p>
  <p>When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.  Note: Softwar…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40060 – When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40060</guid>
    <pubDate>Wed, 13 May 2026 16:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40060</strong></p>
  <p>When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.       Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39458 – When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39458</guid>
    <pubDate>Wed, 13 May 2026 16:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39458</strong></p>
  <p>When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-824</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39455 – When the BIG-IP Configuration utility is configured to use Lightweight Directory...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39455</guid>
    <pubDate>Wed, 13 May 2026 16:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39455</strong></p>
  <p>When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32673 – A vulnerability exists in BIG-IP scripted monitors that may allow an authenticat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32673</guid>
    <pubDate>Wed, 13 May 2026 16:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32673</strong></p>
  <p>A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not eva…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32643 – A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32643</guid>
    <pubDate>Wed, 13 May 2026 16:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32643</strong></p>
  <p>A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28758 – When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28758</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28758</guid>
    <pubDate>Wed, 13 May 2026 16:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28758</strong></p>
  <p>When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is also logged in the audit log. This may allow a highly privileged, authenticated attacker with access to the audit log to view sensitive information.  Note: Software versions which have reached End of Tec…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28758">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2507 – When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2507</guid>
    <pubDate>Wed, 18 Feb 2026 17:21:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2507</strong></p>
  <p>When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22549 – A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22549</guid>
    <pubDate>Wed, 04 Feb 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22549</strong></p>
  <p>A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22548 – When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22548</guid>
    <pubDate>Wed, 04 Feb 2026 15:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22548</strong></p>
  <p>When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-20732 – A vulnerability exists in an undisclosed BIG-IP Configuration utility page that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20732</guid>
    <pubDate>Wed, 04 Feb 2026 15:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-20732</strong></p>
  <p>A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-20730 – A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20730</guid>
    <pubDate>Wed, 04 Feb 2026 15:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-20730</strong></p>
  <p>A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61935 – When a BIG IP Advanced WAF or ASM security policy is configured on a virtual ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61935</guid>
    <pubDate>Wed, 15 Oct 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61935</strong></p>
  <p>When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61933 – A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61933</guid>
    <pubDate>Wed, 15 Oct 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61933</strong></p>
  <p>A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58071 – When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58071</guid>
    <pubDate>Wed, 15 Oct 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58071</strong></p>
  <p>When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61960 – When a per-request policy is configured on a BIG-IP APM portal access virtual se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61960</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61960</strong></p>
  <p>When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61958 – A vulnerability exists in the iHealth command that may allow an authenticated at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61958</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61958</strong></p>
  <p>A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell.  For BIG-IP systems running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not ev…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61938 – When a BIG-IP Advanced WAF or ASM security policy is configured with a URL great...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61938</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61938</strong></p>
  <p>When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process can terminate repeatedly.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59781 – When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59781</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59781</strong></p>
  <p>When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilization.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-459</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59481 – A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59481</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59481</strong></p>
  <p>A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with at least resource administrator role to execute arbitrary system commands with higher privileges.  A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not eval…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59478 – When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59478</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59478</strong></p>
  <p>When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-824</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59269 – A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59269</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59269</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59269</strong></p>
  <p>A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59269">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59268 – On the BIG-IP system, undisclosed endpoints that contain static non-sensitive in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59268</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59268</strong></p>
  <p>On the BIG-IP system, undisclosed endpoints that contain static non-sensitive information are accessible to an unauthenticated remote attacker through the Configuration utility.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58474 – When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58474</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58474</strong></p>
  <p>When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58424 – On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorize...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58424</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58424</strong></p>
  <p>On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity protection.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-340</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58096 – When the database variable tm.tcpudptxchecksum is configured as non-default valu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58096</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58096</strong></p>
  <p>When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-55670 – On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, rep...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55670</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-55670</strong></p>
  <p>On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55669 – When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55669</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55669</strong></p>
  <p>When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-672</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55036 – When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55036</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55036</strong></p>
  <p>When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic may cause memory corruption.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54858 – When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54858</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54858</strong></p>
  <p>When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed JSON schema, and the security policy is applied to a virtual server, undisclosed requests can cause the bd process to terminate.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54854 – When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54854</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54854</strong></p>
  <p>When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53856 – When a virtual server, network address translation (NAT) object, or secure netwo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53856</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53856</strong></p>
  <p>When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  To determine which BIG-IP platforms have an ePVA chip refer to  K12837: Overview of the ePVA feature https://my.f5.com/manage/s/artic…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-705</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-53521 – When a BIG-IP APM access policy is configured on a virtual server, specific mali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53521</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53521</strong></p>
  <p>When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-47148 – When the BIG-IP system is configured as both a Security Assertion Markup Languag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47148</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-47148</strong></p>
  <p>When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41430 – When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41430</guid>
    <pubDate>Wed, 15 Oct 2025 14:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41430</strong></p>
  <p>When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52585 – When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52585</guid>
    <pubDate>Wed, 13 Aug 2025 15:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52585</strong></p>
  <p>When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46405 – When Network Access is configured on a BIG-IP APM virtual server, undisclosed tr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46405</guid>
    <pubDate>Wed, 13 Aug 2025 15:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46405</strong></p>
  <p>When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41431 – When connection mirroring is configured on a virtual server, undisclosed request...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41431</guid>
    <pubDate>Wed, 07 May 2025 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41431</strong></p>
  <p>When connection mirroring is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate in the standby BIG-IP systems in a traffic group.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36525 – When a BIG-IP APM virtual server is configured to use a PingAccess profile, undi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36525</guid>
    <pubDate>Wed, 07 May 2025 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36525</strong></p>
  <p>When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36504 – When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36504</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36504</guid>
    <pubDate>Wed, 07 May 2025 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36504</strong></p>
  <p>When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36504">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-35995 – When a BIG-IP PEM system is licensed with URL categorization, and the URL catego...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-35995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-35995</guid>
    <pubDate>Wed, 07 May 2025 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-35995</strong></p>
  <p>When a BIG-IP PEM system is licensed with URL categorization, and the URL categorization policy or an iRule with the urlcat command is enabled on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-35995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31644 – When running in Appliance mode, a command injection vulnerability exists in an u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31644</guid>
    <pubDate>Wed, 07 May 2025 22:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31644</strong></p>
  <p>When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24326 – When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24326</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24326</strong></p>
  <p>When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case an increase in memory resource utilization.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24320 – A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24320</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24320</strong></p>
  <p>A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. This vulnerability is due to an incomplete fix for  CVE-2024-31156 https://my.f5.com/manage/s/article/K000138636 .   Note: Software versions which have reached End of Technical Support (EoTS) a…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24319 – When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24319</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24319</strong></p>
  <p>When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes service to terminate.        Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24312 – When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24312</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24312</strong></p>
  <p>When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed traffic can cause an increase in CPU resource utilization.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-23415 – An insufficient verification of data authenticity vulnerability exists in BIG-IP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23415</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-23415</strong></p>
  <p>An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection that may allow an attacker to bypass endpoint inspection checks for VPN connection initiated thru BIG-IP APM browser network access VPN client for Windows, macOS and Linux.        Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23413 – When users log in through the webUI or API using local authentication, BIG-IP Ne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23413</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23413</strong></p>
  <p>When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23412 – When BIG-IP APM Access Profile is configured on a virtual server, undisclosed re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23412</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23412</strong></p>
  <p>When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate.        Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22891 – When BIG-IP PEM Control Plane listener Virtual Server is configured with Diamete...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22891</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22891</strong></p>
  <p>When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic can cause the Virtual Server to stop processing new client connections and an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-21091 – When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-21091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-21091</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-21091</strong></p>
  <p>When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20058 – When a BIG-IP message routing profile is configured on a virtual server, undiscl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20058</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20058</strong></p>
  <p>When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20029 – Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20029</guid>
    <pubDate>Wed, 05 Feb 2025 18:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20029</strong></p>
  <p>Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an authenticated attacker to execute arbitrary system commands.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45844 – BIG-IP monitor functionality may allow an attacker to bypass access control rest...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45844</guid>
    <pubDate>Wed, 16 Oct 2024 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45844</strong></p>
  <p>BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41727 – In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41727</guid>
    <pubDate>Wed, 14 Aug 2024 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41727</strong></p>
  <p>In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can cause an increase in memory resource utilization.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-41723 – Undisclosed requests to BIG-IP iControl REST can lead to information leak of use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41723</guid>
    <pubDate>Wed, 14 Aug 2024 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-41723</strong></p>
  <p>Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41723">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-41719 – When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Mana...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41719</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41719</guid>
    <pubDate>Wed, 14 Aug 2024 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-41719</strong></p>
  <p>When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM),  F5 iHealth credentials will be logged in the BIG-IP Central Manager logs.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41719">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39778 – When a stateless virtual server is configured on BIG-IP system with a High-Speed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39778</guid>
    <pubDate>Wed, 14 Aug 2024 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39778</strong></p>
  <p>When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-702</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37028 – BIG-IP Next Central Manager may allow an attacker to lock out an account that ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37028</guid>
    <pubDate>Wed, 14 Aug 2024 15:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37028</strong></p>
  <p>BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-645</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-33612 – An improper certificate validation vulnerability exists in BIG-IP Next Central M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33612</guid>
    <pubDate>Wed, 08 May 2024 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-33612</strong></p>
  <p>An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-33604 – A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33604</guid>
    <pubDate>Wed, 08 May 2024 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-33604</strong></p>
  <p>A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-32761 – Under certain conditions, a data leak may occur in the Traffic Management Microk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32761</guid>
    <pubDate>Wed, 08 May 2024 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-32761</strong></p>
  <p>Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak occurs randomly and cannot be deliberately triggered. If it occurs, it may leak up to 64 bytes of non-contiguous randomized bytes. Under rare conditions, this may lead to a TMM restart, affecting availability.  Note: Software versions wh…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32049 – BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32049</guid>
    <pubDate>Wed, 08 May 2024 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32049</strong></p>
  <p>BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-300</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31156 – A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31156</guid>
    <pubDate>Wed, 08 May 2024 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31156</strong></p>
  <p>A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28883 – An origin validation vulnerability exists in 

BIG-IP APM browser network access...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28883</guid>
    <pubDate>Wed, 08 May 2024 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28883</strong></p>
  <p>An origin validation vulnerability exists in   BIG-IP APM browser network access VPN client      for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-27202 – A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27202</guid>
    <pubDate>Wed, 08 May 2024 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-27202</strong></p>
  <p>A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-26026 – An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (UR...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26026</guid>
    <pubDate>Wed, 08 May 2024 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-26026</strong></p>
  <p>An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25560 – When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25560</guid>
    <pubDate>Wed, 08 May 2024 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25560</strong></p>
  <p>When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21793 – An OData injection vulnerability exists in the BIG-IP Next Central Manager API (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21793</guid>
    <pubDate>Wed, 08 May 2024 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21793</strong></p>
  <p>An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23982 – When a BIG-IP PEM classification profile is configured on a UDP virtual server, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23982</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23982</strong></p>
  <p>When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This issue affects classification engines using signatures released between 09-08-2022 and 02-16-2023. See the table in the F5 Security Advisory for a complete list of affected classification signature files.  NOTE: Software versions…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23976 – When running in Appliance mode, an authenticated attacker assigned the Administr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23976</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23976</strong></p>
  <p>When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a BIG-IP system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23805 – Undisclosed requests can cause the Traffic Management Microkernel (TMM) to termi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23805</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23805</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23805</strong></p>
  <p>Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics profile with URLs enabled under Collected Entities is configured on a virtual server and the DB variables avr.IncludeServerInURI or avr.CollectOnlyHostnameFromURI are enabled. For BIG-IP Advanced WAF and ASM, this may occ…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23805">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-23603 – An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Confi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23603</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-23603</strong></p>
  <p>An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility.      Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23314 – When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed resp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23314</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23314</strong></p>
  <p>When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23308 – When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling opt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23308</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23308</strong></p>
  <p>When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause the BD process to terminate. The condition results from setting the Request Body Handling option in the Header-Based Content Profile for an Allowed URL with "Apply value and content signatures and detect threat campaigns."  Note: Software versions whi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23306 – A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23306</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23306</strong></p>
  <p>A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22389 – When BIG-IP is deployed in high availability (HA) and an iControl REST API token...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22389</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22389</strong></p>
  <p>When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device.     Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21789 – When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21789</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21789</strong></p>
  <p>When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21782 – BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have acces...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21782</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21782</strong></p>
  <p>BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) can execute arbitrary commands with a specially crafted command string. This vulnerability is due to an incomplete fix for CVE-2020-5873.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21771 – For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21771</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21771</strong></p>
  <p>For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel (TMM) restarting and traffic disruption.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21763 – When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21763</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21763</strong></p>
  <p>When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffic Management Microkernel (TMM) to terminate.  NOTE: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46748 – An authenticated SQL injection vulnerability exists in the BIG-IP Configuration ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46748</guid>
    <pubDate>Thu, 26 Oct 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46748</strong></p>
  <p>An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which   may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-46747 – Undisclosed requests may bypass configuration utility authentication, allowing a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46747</guid>
    <pubDate>Thu, 26 Oct 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-46747</strong></p>
  <p>Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46747">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
