F5
Big-IP
See the latest tracked release, confirm when it was published, and subscribe for update emails.
21.1.0
- Release date
- May 15, 2026
- Security status
- 19 high-severity CVEs tracked in the last 90 days. Current version impact is unclear.
Source
Vendor Release Information
Public release notes are linked for the latest stored release.
Release history
See the latest published releases stored for this product.
| Version | Published | Notes |
|---|---|---|
| 21.1.0 | 2026-05-15 | Release Notes |
Vulnerability tracking
versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.
Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.
| CVE | Severity | Published | Status | Summary |
|---|---|---|---|---|
| CVE-2026-42937 | HIGH (7.1) | 2026-05-13 | Current versionnot affected | Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view adjacent network information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-42930 | HIGH (8.7) | 2026-05-13 | Current versionnot affected | When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-42919 | HIGH (7.1) | 2026-05-13 | Current versionnot affected | A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-42406 | HIGH (8.7) | 2026-05-13 | Current versionnot affected | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-41959 | HIGH (7.1) | 2026-05-13 | Current versionnot affected | Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view the network status of destination systems. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-41957 | HIGH (8.8) | 2026-05-13 | Current versionunclear | An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 1 more
|
| CVE-2026-41953 | HIGH (8.7) | 2026-05-13 | Current versionnot affected | A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-41219 | HIGH (7.1) | 2026-05-13 | Current versionunclear | An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated Affected versions
Show 1 more
|
| CVE-2026-41218 | HIGH (8.7) | 2026-05-13 | Current versionnot affected | When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-41217 | HIGH (8.3) | 2026-05-13 | Current versionnot affected | A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-40698 | HIGH (8.7) | 2026-05-13 | Current versionnot affected | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-40618 | HIGH (8.7) | 2026-05-13 | Current versionnot affected | When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 6 more
|
| CVE-2026-40067 | HIGH (8.7) | 2026-05-13 | Current versionnot affected | When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-40061 | HIGH (8.7) | 2026-05-13 | Current versionnot affected | When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-40060 | HIGH (8.7) | 2026-05-13 | Current versionnot affected | When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-39458 | HIGH (8.7) | 2026-05-13 | Current versionnot affected | When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-39455 | HIGH (8.7) | 2026-05-13 | Current versionnot affected | When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-32673 | HIGH (8.7) | 2026-05-13 | Current versionnot affected | A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-32643 | HIGH (8.7) | 2026-05-13 | Current versionnot affected | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|