Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,016
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,641 - 3,660 of 12,518 CVEs
CVE-2026-41956 HIGH - 7.5

When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP, BIG-IP Next CNF, BIG-IP Next for Kubernetes
Published: May 13, 2026
Source: NVD
CVE-2026-41953 HIGH - 8.7

A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-41227 HIGH - 7.5

On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated...

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-41218 HIGH - 7.5

When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached En...

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-41217 HIGH - 7.9

A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker...

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-40698 HIGH - 8.7

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege escalation.  Note: Software versions which h...

Vendor: F5
Product: BIG-IP, BIG-IQ
Published: May 13, 2026
Source: NVD
CVE-2026-40631 HIGH - 8.7

An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-40629 HIGH - 7.5

When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP, BIG-IP Next SPK, BIG-IP Next CNF, BIG-IP Next for Kubernetes
Published: May 13, 2026
Source: NVD
CVE-2026-40618 HIGH - 7.5

When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to ...

Vendor: F5
Product: BIG-IP, BIG-IP Next SPK, BIG-IP Next CNF, BIG-IP Next for Kubernetes
Published: May 13, 2026
Source: NVD
CVE-2026-40423 HIGH - 7.5

When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-40067 HIGH - 7.5

When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-40061 HIGH - 8.7

When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In Appliance mode de...

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-40060 HIGH - 7.5

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-39459 HIGH - 7.2

A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.  Note: Software versions which have reached End of Technical Support (EoTS) are ...

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-39458 HIGH - 7.5

When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-39455 HIGH - 7.5

When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors.  Note: Software versions which have reached End of Technical Support (EoTS) are not evalu...

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-36741 HIGH - 7.2

U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol (NTP) configuration interface does not properly sanitize user-supplied input. An authenticated user with permission to configure NTP settings can inject arbitrary system commands t...

Published: May 13, 2026
Source: NVD
CVE-2026-34176 HIGH - 8.7

When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.   Note: Software versions which have reached End of Technical Support (EoTS) are not eva...

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-32673 HIGH - 8.7

A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a securit...

Vendor: F5
Product: BIG-IP
Published: May 13, 2026
Source: NVD
CVE-2026-32643 HIGH - 8.7

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not...

Vendor: F5
Product: BIG-IP, BIG-IQ
Published: May 13, 2026
Source: NVD