Back to search

F5

Big-IP

See the latest tracked release, confirm when it was published, and subscribe for update emails.

Current version
Last checked: 2026-09-04

14.1.5

Release date
July 07, 2026
Security status
Current version appears affected by 8 high-severity CVEs.

Source

Vendor Release Information

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
14.1.5 2026-07-07 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-66842 HIGH (8.7) 2026-09-02 Current versionunclear

BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.1.0 - Up to (excluding) 21.1.0.1
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.3
Show 2 more
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.8
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.4
CVE-2026-59762 HIGH (8.7) 2026-07-15 Current versionunclear

When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.   Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.1.0 - Up to (excluding) 21.1.0.1
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.3
Show 2 more
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.8
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.4
CVE-2023-46748 HIGH (8.8) 2023-10-26 Current versionaffected

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected versions
  • From (including) 17.1.0 - Up to (excluding) *
  • From (including) 16.1.0 - Up to (excluding) *
Show 3 more
  • From (including) 15.1.0 - Up to (excluding) *
  • From (including) 14.1.0 - Up to (excluding) *
  • From (including) 13.1.0 - Up to (excluding) *
CVE-2023-46747 CRITICAL (9.8) 2023-10-26 Current versionaffected

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected versions
  • From (including) 17.1.0 - Up to (excluding) *
  • From (including) 16.1.0 - Up to (excluding) *
Show 3 more
  • From (including) 15.1.0 - Up to (excluding) *
  • From (including) 14.1.0 - Up to (excluding) *
  • From (including) 13.1.0 - Up to (excluding) *
CVE-2023-43746 HIGH (8.7) 2023-10-10 Current versionaffected

When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system.  A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 16.1.0 - Up to (excluding) 16.1.4
  • From (including) 15.1.0 - Up to (excluding) 15.1.9
Show 2 more
  • From (including) 14.1.0 - Up to (excluding) *
  • From (including) 13.1.0 - Up to (excluding) *
CVE-2023-42768 HIGH (7.2) 2023-10-10 Current versionaffected

When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP non-admin user can still have access to iControl REST admin resource.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 16.1.0 - Up to (excluding) 16.1.4
  • From (including) 15.1.0 - Up to (excluding) 15.1.9
Show 2 more
  • From (including) 14.1.0 - Up to (excluding) *
  • From (including) 13.1.0 - Up to (excluding) *
CVE-2023-41373 CRITICAL (9.9) 2023-10-10 Current versionaffected

A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 17.1.0 - Up to (excluding) 17.1.0.3
  • From (including) 16.1.0 - Up to (excluding) 16.1.4.1
Show 3 more
  • From (including) 15.1.0 - Up to (excluding) 15.1.10.2
  • From (including) 14.1.0 - Up to (excluding) 14.1.5.6
  • From (including) 13.1.0 - Up to (excluding) *
CVE-2023-41085 HIGH (7.5) 2023-10-10 Current versionaffected

When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 16.1.0 - Up to (excluding) 16.1.4
  • From (including) 15.1.0 - Up to (excluding) 15.1.9
Show 2 more
  • From (including) 14.1.0 - Up to (excluding) *
  • From (including) 13.1.0 - Up to (excluding) *
CVE-2023-40542 HIGH (7.5) 2023-10-10 Current versionaffected

When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected versions
  • From (including) 16.1.0 - Up to (excluding) 16.1.4
  • From (including) 15.1.0 - Up to (excluding) 15.1.9
Show 2 more
  • From (including) 14.1.0 - Up to (excluding) *
  • From (including) 13.1.0 - Up to (excluding) *
CVE-2023-40537 HIGH (8.1) 2023-10-10 Current versionaffected

An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade VIPRION platform.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 16.1.0 - Up to (excluding) 16.1.4
  • From (including) 15.1.0 - Up to (excluding) 15.1.9
Show 2 more
  • From (including) 14.1.0 - Up to (excluding) *
  • From (including) 13.1.0 - Up to (excluding) *