F5
Big-IP
See the latest tracked release, confirm when it was published, and subscribe for update emails.
21.1.0.2
- Release date
- September 01, 2026
- Security status
- Current version appears affected by 1 high-severity CVE.
Source
Vendor Release Information
Public release notes are linked for the latest stored release.
Release history
See the latest published releases stored for this product.
| Version | Published | Notes |
|---|---|---|
| 21.1.0.2 | 2026-09-01 | Release Notes |
| 21.1.0.1 | 2026-07-15 | Release Notes |
| 21.1.0 | 2026-05-15 | Release Notes |
Vulnerability tracking
versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.
Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.
| CVE | Severity | Published | Status | Summary |
|---|---|---|---|---|
| CVE-2026-66842 | HIGH (8.7) | 2026-09-02 | Current versionnot affected | BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2026-59762 | HIGH (8.7) | 2026-07-15 | Current versionnot affected | When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 2 more
|
| CVE-2024-25560 | HIGH (7.5) | 2024-05-08 | Current versionaffected | When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Affected versions
Show 1 more
|