CVE-2026-94127
- EPSS 1.29%
- Veröffentlicht 22.09.2026 14:17:42
- Zuletzt bearbeitet 23.09.2026 14:32:07
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Se...
CVE-2026-63020
- EPSS 0.19%
- Veröffentlicht 02.09.2026 15:40:53
- Zuletzt bearbeitet 15.09.2026 18:19:18
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error...
CVE-2026-66842
- EPSS 0.25%
- Veröffentlicht 02.09.2026 15:40:53
- Zuletzt bearbeitet 03.09.2026 13:06:01
BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticat...
CVE-2026-59762
- EPSS 0.46%
- Veröffentlicht 15.07.2026 14:33:44
- Zuletzt bearbeitet 06.08.2026 18:20:20
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually re...
CVE-2026-40423
- EPSS 0.26%
- Veröffentlicht 13.05.2026 14:12:43
- Zuletzt bearbeitet 29.06.2026 14:16:21
When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-24464
- EPSS 0.89%
- Veröffentlicht 13.05.2026 14:12:42
- Zuletzt bearbeitet 29.06.2026 18:00:40
When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files. Note: Soft...
CVE-2026-39458
- EPSS 0.26%
- Veröffentlicht 13.05.2026 14:12:42
- Zuletzt bearbeitet 24.08.2026 22:16:52
When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WAF DoS protection), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions wh...
CVE-2026-42930
- EPSS 0.48%
- Veröffentlicht 13.05.2026 14:12:42
- Zuletzt bearbeitet 13.05.2026 16:27:11
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not eva...
CVE-2026-41959
- EPSS 0.2%
- Veröffentlicht 13.05.2026 14:12:41
- Zuletzt bearbeitet 24.06.2026 14:52:18
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view the network status of destination...
CVE-2026-42406
- EPSS 0.15%
- Veröffentlicht 13.05.2026 14:12:41
- Zuletzt bearbeitet 23.06.2026 13:57:09
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which...