VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 805 of 1286 · EPSS data 2026.08.09
ReviewHigh
CVE-2026-41218

F5 BIG-IP, big-ip access policy manager, big-ip advanced firewall manager

When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-41217

F5 BIG-IP, big-ip access policy manager, big-ip advanced firewall manager

A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40698

F5 BIG-IP, BIG-IQ, big-ip access policy manager

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40629

F5 BIG-IP, BIG-IP Next SPK, BIG-IP Next CNF

When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40618

F5 BIG-IP, BIG-IP Next SPK, BIG-IP Next CNF

When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40067

F5 BIG-IP, big-ip access policy manager

When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-40061

F5 BIG-IP, big-ip domain name system

When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-39459

F5 BIG-IP, big-ip access policy manager, big-ip advanced firewall manager

A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-39455

F5 BIG-IP, big-ip access policy manager, big-ip advanced firewall manager

When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.