Back to search

F5

Big-IP

See the latest tracked release, confirm when it was published, and subscribe for update emails.

Current version
Last checked: 2026-09-04

16.1.6.1

Release date
July 07, 2026
Security status
Current version appears affected by 42 high-severity CVEs.

Source

Vendor Release Information

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
16.1.6.1 2026-07-07 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-66842 HIGH (8.7) 2026-09-02 Current versionunclear

BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.1.0 - Up to (excluding) 21.1.0.1
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.3
Show 2 more
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.8
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.4
CVE-2026-59762 HIGH (8.7) 2026-07-15 Current versionunclear

When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.   Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.1.0 - Up to (excluding) 21.1.0.1
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.3
Show 2 more
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.8
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.4
CVE-2026-40423 HIGH (8.7) 2026-05-13 Current versionaffected

When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-42930 HIGH (8.5) 2026-05-13 Current versionaffected

When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-39458 HIGH (8.7) 2026-05-13 Current versionaffected

When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WAF DoS protection), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.1
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-41959 HIGH (7.1) 2026-05-13 Current versionaffected

Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view the network status of destination systems.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-42406 HIGH (8.5) 2026-05-13 Current versionaffected

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.     Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-32643 HIGH (8.5) 2026-05-13 Current versionaffected

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-42937 HIGH (7.1) 2026-05-13 Current versionaffected

Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view adjacent network information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-39455 HIGH (8.7) 2026-05-13 Current versionaffected

When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-32673 HIGH (8.5) 2026-05-13 Current versionaffected

A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-41217 HIGH (8.3) 2026-05-13 Current versionaffected

A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-34176 HIGH (8.5) 2026-05-13 Current versionaffected

When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-41225 HIGH (8.6) 2026-05-13 Current versionaffected

A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-39459 HIGH (8.6) 2026-05-13 Current versionaffected

A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-41953 HIGH (8.5) 2026-05-13 Current versionaffected

A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-40631 HIGH (8.5) 2026-05-13 Current versionaffected

An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-40698 HIGH (8.5) 2026-05-13 Current versionaffected

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.2
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.6
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.2
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-42924 HIGH (8.5) 2026-05-13 Current versionaffected

An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.1
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-40060 HIGH (8.7) 2026-05-13 Current versionaffected

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.1
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-42409 HIGH (8.7) 2026-05-13 Current versionaffected

When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.1
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-41227 HIGH (8.7) 2026-05-13 Current versionaffected

On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
Show 1 more
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-40061 HIGH (8.5) 2026-05-13 Current versionaffected

When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.1
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-35062 HIGH (7.1) 2026-05-13 Current versionaffected

An authenticated iControl SOAP user may be able to obtain information of other accounts.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.1
  • From (including) 17.5.1 - Up to (excluding) 17.5.1.4
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-40618 HIGH (8.7) 2026-05-13 Current versionaffected

When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.1
  • From (including) 17.5.0 - Up to (excluding) 17.1.5.4
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-41956 HIGH (8.7) 2026-05-13 Current versionaffected

When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
Show 1 more
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-42920 HIGH (8.7) 2026-05-13 Current versionaffected

When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.1
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-40629 HIGH (8.7) 2026-05-13 Current versionaffected

When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
Show 1 more
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-42919 HIGH (7.1) 2026-05-13 Current versionaffected

A vulnerability exists in BIG-IP systems that may allow an authenticated attacker with administrative access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.1
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-41218 HIGH (8.7) 2026-05-13 Current versionaffected

When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.1
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-41957 HIGH (8.7) 2026-05-13 Current versionaffected

An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
Show 1 more
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-40067 HIGH (8.7) 2026-05-13 Current versionaffected

When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.1
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-40699 HIGH (7.1) 2026-05-13 Current versionaffected

A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticated attacker to access to undisclosed sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.1
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-41219 HIGH (7.1) 2026-05-13 Current versionaffected

An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected versions
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
Show 1 more
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2026-40462 HIGH (7.1) 2026-05-13 Current versionaffected

Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which may allow an authenticated attacker to view sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 21.0.0 - Up to (excluding) 21.0.0.1
  • From (including) 17.5.0 - Up to (excluding) 17.5.1.4
Show 2 more
  • From (including) 17.1.0 - Up to (excluding) 17.1.3.1
  • From (including) 16.1.0 - Up to (excluding) *
CVE-2025-48500 HIGH (7.0) 2025-08-13 Current versionaffected

A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 17.5.0 - Up to (excluding) *
  • From (including) 17.1.0 - Up to (excluding) *
Show 2 more
  • From (including) 16.1.0 - Up to (excluding) *
  • From (including) 15.1.0 - Up to (excluding) *
CVE-2025-24312 HIGH (8.7) 2025-02-05 Current versionaffected

When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed traffic can cause an increase in CPU resource utilization.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 17.1.0 - Up to (excluding) 17.1.2
  • From (including) 16.1.0 - Up to (excluding) *
Show 1 more
  • From (including) 15.1.0 - Up to (excluding) *
CVE-2025-20058 HIGH (8.9) 2025-02-05 Current versionaffected

When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected versions
  • From (including) 17.1.0 - Up to (excluding) 17.1.2
  • From (including) 16.1.0 - Up to (excluding) *
Show 1 more
  • From (including) 15.1.0 - Up to (excluding) *
CVE-2025-21091 HIGH (8.7) 2025-02-05 Current versionaffected

When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected versions
  • From (including) 17.1.0 - Up to (excluding) 17.1.2
  • From (including) 16.1.0 - Up to (excluding) *
Show 1 more
  • From (including) 15.1.0 - Up to (excluding) *
CVE-2025-21087 HIGH (8.9) 2025-02-05 Current versionaffected

When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an increase in memory and CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected versions
  • From (including) 17.1.0 - Up to (excluding) 17.1.2
  • From (including) 16.1.0 - Up to (excluding) *
Show 1 more
  • From (including) 15.1.0 - Up to (excluding) *
CVE-2024-25560 HIGH (7.5) 2024-05-08 Current versionaffected

When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected versions
  • From (including) 17.1.0 - Up to (excluding) 17.1.1
  • From (including) 16.1.0 - Up to (excluding) 16.1.4
Show 1 more
  • From (including) 15.1.0 - Up to (excluding) *
CVE-2024-21789 HIGH (7.5) 2024-02-14 Current versionaffected

When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected versions
  • From (including) 17.1.0 - Up to (excluding) 17.1.1
  • From (including) 16.1.0 - Up to (including) *
Show 1 more
  • From (including) 15.1.0 - Up to (including) *
CVE-2023-46748 HIGH (8.8) 2023-10-26 Current versionaffected

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected versions
  • From (including) 17.1.0 - Up to (excluding) *
  • From (including) 16.1.0 - Up to (excluding) *
Show 3 more
  • From (including) 15.1.0 - Up to (excluding) *
  • From (including) 14.1.0 - Up to (excluding) *
  • From (including) 13.1.0 - Up to (excluding) *
CVE-2023-46747 CRITICAL (9.8) 2023-10-26 Current versionaffected

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Affected versions
  • From (including) 17.1.0 - Up to (excluding) *
  • From (including) 16.1.0 - Up to (excluding) *
Show 3 more
  • From (including) 15.1.0 - Up to (excluding) *
  • From (including) 14.1.0 - Up to (excluding) *
  • From (including) 13.1.0 - Up to (excluding) *