Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · f5

f5

· 47 Critical

Total CVEs

973

Critical

47

Products

284

Search All CVEs →

973

Products (284)

big-ip access policy manager589 CVEsbig-ip application security manager540 CVEsbig-ip advanced firewall manager513 CVEsbig-ip local traffic manager502 CVEsbig-ip policy enforcement manager494 CVEsbig-ip link controller486 CVEsbig-ip application acceleration manager485 CVEsbig-ip analytics472 CVEsbig-ip global traffic manager451 CVEsbig-ip domain name system428 CVEsbig-ip fraud protection service366 CVEsbig-ip webaccelerator258 CVEsbig-ip edge gateway254 CVEsbig-ip advanced web application firewall154 CVEsbig-ip websafe136 CVEsbig-ip ddos hybrid defender126 CVEsbig-ip ssl orchestrator107 CVEsbig-iq centralized management77 CVEsbig-ip carrier-grade nat70 CVEsbig-ip application visibility and reporting69 CVEsbig-ip protocol security module61 CVEsbig-ip container ingress services47 CVEsbig-ip automation toolchain46 CVEsnginx41 CVEsnjs40 CVEsenterprise manager39 CVEsbig-ip wan optimization manager38 CVEstraffix signaling delivery controller31 CVEsssl orchestrator27 CVEsbig-ip next cloud-native network functions22 CVEsbig-ip next service proxy for kubernetes21 CVEsbig-iq cloud20 CVEsbig-iq security20 CVEsbig-iq device20 CVEsnginx plus20 CVEsbig-ip access policy manager client20 CVEsnginx controller18 CVEsnginx open source17 CVEsiworkflow17 CVEsf5os-a17 CVEsf5os-c14 CVEsbig-ip dns14 CVEsbig-iq cloud and orchestration13 CVEsbig-ip next central manager12 CVEsbig-ip enterprise manager10 CVEsfirepass10 CVEsnginx ingress controller10 CVEsbig-iq application delivery controller9 CVEsnginx instance manager8 CVEsarx8 CVEsbig-ip next for kubernetes8 CVEsbig-iq adc7 CVEsbig-ip protocol security manager7 CVEstmos7 CVEsfirepass 41007 CVEsbig-ip guided configuration6 CVEsbig-ip i108005 CVEsaccess policy manager clients5 CVEsbig-ip i106005 CVEsbig-ip i76004 CVEsbig-ip i78004 CVEsbig-ip i116004 CVEsbig-ip i158004 CVEsbig-ip i56004 CVEsbig-ip i58004 CVEsarx firmware4 CVEsf5 iworkflow4 CVEsbig-ip i156004 CVEsbig-ip i118004 CVEsfirepass ssl vpn3 CVEsbig-ip3 CVEsnginx api connectivity manager3 CVEsbig-ip service proxy3 CVEswebsafe alert server3 CVEsbig-ip edge3 CVEsbig-ip pem2 CVEsbig-ip 10000s2 CVEsbig-ip 10000s firmware2 CVEsbig-ip afm2 CVEsbig-ip apm2 CVEsbig-ip asm2 CVEsbig-ip controller2 CVEsbig-ip fraud protection services2 CVEsbig-ip i10600 firmware2 CVEsbig-ip i10800 firmware2 CVEsbig-ip i11600 firmware2 CVEsbig-ip i11800 firmware2 CVEsbig-ip i15600 firmware2 CVEsbig-ip i15800 firmware2 CVEsbig-ip i26002 CVEsbig-ip i5600 firmware2 CVEsbig-ip i5800 firmware2 CVEsbig-ip i7600 firmware2 CVEsbig-ip i7800 firmware2 CVEsbig-ip i8502 CVEsbig-ip ltm2 CVEsbig-ip next2 CVEsnginx agent2 CVEsnginx gateway fabric2 CVEsnginx security monitoring2 CVEsnginx unit2 CVEsr106002 CVEsr108002 CVEsr109002 CVEsr56002 CVEsr58002 CVEsr59002 CVEsssl intercept iapp2 CVEstraffix systems signaling delivery controller2 CVEswebsafe2 CVEsbig-ip 64001 CVEsbig-ip edge client1 CVEsbig-ip 5250v-f firmware1 CVEsbig-ip 5250v-f1 CVEsbig-ip 5200v firmware1 CVEsbig-ip 10050s1 CVEsbig-ip 5200v-ssl firmware1 CVEsbig-ip global traffic manager11.2.01 CVEsbig-ip 5200v-ssl1 CVEsbig-ip 5200v1 CVEsbig-ip 10001 CVEsbig-ip 51101 CVEsarx data manager1 CVEsbig-ip 51001 CVEsapplication security manager appliance1 CVEsbig-ip 5000s firmware1 CVEsvelos bx1101 CVEsbig-ip 5000s1 CVEsvelos bx110 firmware1 CVEsbig-ip 4200v1 CVEsvelos cx16101 CVEsbig-ip i15820-df1 CVEsbig-ip i15820-df firmware1 CVEsbig-ip i20001 CVEsbig-ip i2000s1 CVEsbig-ip i2200s1 CVEsvelos cx4101 CVEsbig-ip i28001 CVEsbig-ip i40001 CVEsbig-ip i4000s1 CVEsbig-ip i4200v1 CVEsbig-ip i46001 CVEsbig-ip i48001 CVEsbig-ip i5000s1 CVEsbig-ip i5050s1 CVEsbig-ip i5200v1 CVEsbig-ip i5250v1 CVEsbig-ip i5250v fips1 CVEsbig-ip 41001 CVEsviprion 2100 blades1 CVEsbig-ip 4000s1 CVEsviprion 22001 CVEsbig-ip i5820-df1 CVEsbig-ip i5820-df firmware1 CVEsbig-ip i70001 CVEsbig-ip i7050s1 CVEsbig-ip i7055s1 CVEsbig-ip i7200v1 CVEsbig-ip i7200v-ssl1 CVEsbig-ip i7200v fips1 CVEsbig-ip i7250v1 CVEsbig-ip i7255s1 CVEsbig-ip 40001 CVEsviprion 2200 firmware1 CVEsbig-ip 39001 CVEsviprion 4200 blades1 CVEsbig-ip i7820-df1 CVEsbig-ip i7820-df firmware1 CVEsviprion 4300 blades1 CVEsbig-ip 36001 CVEsbig-ip 34101 CVEsviprion 4450 blades1 CVEsviprion application delivery controller1 CVEsbig-ip 34001 CVEsbig-ip 28001 CVEsbig-ip 24001 CVEsbig-ip 2200s1 CVEsaccess for android1 CVEsbig-ip 2000s1 CVEsbig-ip policy enforcement manager11.5.11 CVEsbig-ip policy webaccelerator1 CVEsbig-ip 20001 CVEsbig-ip 16001 CVEsbig-ip 15001 CVEsbig-ip 12250v firmware1 CVEsbig-ip virtual edition1 CVEsbig-ip 12250v1 CVEsbig-ip 12000 firmware1 CVEsbig-ip webaccelerator12.1.11 CVEsbig-ip 120001 CVEsbig-iq1 CVEsbig-ip 11050-f firmware1 CVEsbig-ip 11050-f1 CVEsbig-ip 110501 CVEsbig-ip 11000-f firmware1 CVEsbig-ip 11000-f1 CVEsbig-ip 110001 CVEsbig-ip 10350v-n firmware1 CVEscontainer ingress service1 CVEsdos1 CVEsbig-ip 10350v-n1 CVEsf5 access1 CVEsbig-ip 10350v-f firmware1 CVEsf5 websafe1 CVEsf5os1 CVEsbig-ip 10350v-f1 CVEsbig-ip 10250v firmware1 CVEsbig-ip 10250v1 CVEsfirepass 10001 CVEsfirepass 12001 CVEsbig-ip 10200v firmware1 CVEsbig-ip 10200v-ssl firmware1 CVEsicontrol service manager1 CVEsbig-ip 10200v-ssl1 CVEslinerate1 CVEsmobilesafe1 CVEsbig-ip 10200v-s firmware1 CVEsviprion b21001 CVEsbig-ip 10200v-s1 CVEsnginx app protect1 CVEsnginx app protect dos1 CVEsnginx app protect waf1 CVEsbig-ip 10200v-f firmware1 CVEsnginx controller api management1 CVEsviprion b2100 firmware1 CVEsbig-ip 10200v-f1 CVEsbig-ip 10200v1 CVEsnginx modsecurity waf1 CVEsbig-ip 10150v-n firmware1 CVEsnginx openid connect1 CVEsbig-ip 10150v-n1 CVEsviprion b21501 CVEsnginx service mesh1 CVEsviprion b2150 firmware1 CVEsbig-ip 10050s firmware1 CVEsviprion b22501 CVEsr10600 firmware1 CVEsviprion b2250 firmware1 CVEsr10800 firmware1 CVEsviprion b43001 CVEsr10900 firmware1 CVEsr10920-df1 CVEsr12600-ds1 CVEsr12800-ds1 CVEsr12900-ds1 CVEsr20001 CVEsr40001 CVEsviprion b4300 firmware1 CVEsr5600 firmware1 CVEsviprion b44501 CVEsr5800 firmware1 CVEsviprion b4450 firmware1 CVEsbig-ip 89001 CVEsbig-ip 8900-f1 CVEsbig-ip 8900-f firmware1 CVEsbig-ip 89501 CVEsbig-ip 88001 CVEsbig-ip 84001 CVEsbig-ip 7200v firmware1 CVEsbig-ip 7200v-ssl firmware1 CVEsr5900 firmware1 CVEsbig-ip 7200v-ssl1 CVEsr5920-df1 CVEsbig-ip 7200v-f firmware1 CVEsbig-ip 7200v-f1 CVEsbig-ip 7200v1 CVEssilverline1 CVEsbig-ip 7000s firmware1 CVEsbig-ip b22501 CVEsbig-ip b2250 firmware1 CVEsbig-ip b43001 CVEsbig-ip b4300 firmware1 CVEsbig-ip b4340n1 CVEsbig-ip b4340n firmware1 CVEsbig-ip b4450n1 CVEsbig-ip b4450n firmware1 CVEsbig-ip 7000s1 CVEsbig-ip configuration utility1 CVEsbig-ip 6900-f firmware1 CVEswaf1 CVEsbig-ip datasafe1 CVEsbig-ip 6900-f1 CVEsbig-ip 69001 CVEsbig-ip 68001 CVEs

Recent Vulnerabilities

View all 973
CVE-2026-42055HIGH 8.1

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-9256HIGH 8.1

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-8711HIGH 8.1

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-32647HIGH 7.8

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-28755MEDIUM 5.4

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-28753LOW 3.7

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-27784HIGH 7.8

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-27654HIGH 8.2

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-27651HIGH 7.5

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-22549MEDIUM 4.9

A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secrets.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-22548MEDIUM 5.9

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-20732LOW 3.1

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-20730LOW 3.3

A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2026-1642MEDIUM 5.9

A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-14727HIGH 8.3

A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61990HIGH 7.5

When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61935HIGH 7.5

When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61933MEDIUM 6.1

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-58071HIGH 7.5

When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-57780HIGH 8.8

A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges.  A successful exploit may allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-53860MEDIUM 4.1

A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries systems.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61974HIGH 7.5

When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61960HIGH 7.5

When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61958HIGH 8.7

A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell.  For BIG-IP systems running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-61955HIGH 8.8

A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escalate their privileges.  A successful exploit may allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.