CVE-2026-40060
- EPSS 0.07%
- Veröffentlicht 13.05.2026 14:12:35
- Zuletzt bearbeitet 13.05.2026 16:27:11
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-41227
- EPSS 0.07%
- Veröffentlicht 13.05.2026 14:12:35
- Zuletzt bearbeitet 13.05.2026 16:27:11
On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached...
CVE-2026-42409
- EPSS 0.08%
- Veröffentlicht 13.05.2026 14:12:35
- Zuletzt bearbeitet 13.05.2026 16:27:11
When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions whic...
CVE-2026-35062
- EPSS 0.05%
- Veröffentlicht 13.05.2026 14:12:34
- Zuletzt bearbeitet 13.05.2026 16:27:11
An authenticated iControl SOAP user may be able to obtain information of other accounts. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-40061
- EPSS 0.05%
- Veröffentlicht 13.05.2026 14:12:34
- Zuletzt bearbeitet 13.05.2026 16:27:11
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system com...
CVE-2026-40618
- EPSS 0.07%
- Veröffentlicht 13.05.2026 14:12:33
- Zuletzt bearbeitet 13.05.2026 16:27:11
When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can ...
CVE-2026-41956
- EPSS 0.07%
- Veröffentlicht 13.05.2026 14:12:33
- Zuletzt bearbeitet 13.05.2026 16:27:11
When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-42920
- EPSS 0.07%
- Veröffentlicht 13.05.2026 14:12:33
- Zuletzt bearbeitet 13.05.2026 16:27:11
When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Suppor...
CVE-2026-40629
- EPSS 0.07%
- Veröffentlicht 13.05.2026 14:12:32
- Zuletzt bearbeitet 13.05.2026 16:27:11
When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2026-41218
- EPSS 0.07%
- Veröffentlicht 13.05.2026 14:12:32
- Zuletzt bearbeitet 13.05.2026 16:27:11
When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to termina...