CVE-2026-41953
- EPSS 0.25%
- Veröffentlicht 13.05.2026 14:12:37
- Zuletzt bearbeitet 24.06.2026 14:52:04
A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escalation. Note: Software versions which have reached E...
CVE-2026-40631
- EPSS 0.25%
- Veröffentlicht 13.05.2026 14:12:36
- Zuletzt bearbeitet 29.06.2026 14:17:42
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are ...
CVE-2026-40698
- EPSS 0.24%
- Veröffentlicht 13.05.2026 14:12:36
- Zuletzt bearbeitet 29.06.2026 15:30:00
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in priv...
CVE-2026-42924
- EPSS 0.25%
- Veröffentlicht 13.05.2026 14:12:36
- Zuletzt bearbeitet 13.05.2026 16:27:11
An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS)...
CVE-2026-40060
- EPSS 0.32%
- Veröffentlicht 13.05.2026 14:12:35
- Zuletzt bearbeitet 29.06.2026 14:15:34
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-41227
- EPSS 0.26%
- Veröffentlicht 13.05.2026 14:12:35
- Zuletzt bearbeitet 24.06.2026 14:52:01
On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached...
CVE-2026-42409
- EPSS 0.26%
- Veröffentlicht 13.05.2026 14:12:35
- Zuletzt bearbeitet 23.06.2026 13:58:18
When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions whic...
CVE-2026-35062
- EPSS 0.25%
- Veröffentlicht 13.05.2026 14:12:34
- Zuletzt bearbeitet 29.06.2026 17:27:55
An authenticated iControl SOAP user may be able to obtain information of other accounts. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-40061
- EPSS 0.24%
- Veröffentlicht 13.05.2026 14:12:34
- Zuletzt bearbeitet 29.06.2026 17:23:27
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system com...
CVE-2026-40618
- EPSS 0.32%
- Veröffentlicht 13.05.2026 14:12:33
- Zuletzt bearbeitet 29.06.2026 14:17:27
When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can ...