Technology · F5
F5 BIG-IP Advanced WAF vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 19 vulnerabilities in F5 BIG-IP Advanced WAF: 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-42930, was published on 13 May 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 1
- Exploited in the wild
- 0
About F5 BIG-IP Advanced WAF
A web application firewall designed to protect applications against automated attacks and web vulnerabilities.
Latest F5 BIG-IP Advanced WAF vulnerabilities
- CVE-2026-42930: F5 BIG-IP Appliance mode restriction bypass via path traversalhighCVSS 8.7EPSS 0.5%
- CVE-2026-42924: F5 BIG-IP privilege escalation in iControl SOAP via SNMP configurationhighCVSS 8.7EPSS 0.3%
- CVE-2026-42919: F5 BIG-IP privilege escalation in multiple modulesmediumCVSS 6.7EPSS 0.3%
- CVE-2026-42409: F5 BIG-IP DoS via HTTP/2 iRule redirectionhighCVSS 7.5EPSS 0.3%
- CVE-2026-42063: F5 BIG-IP sensitive file download in iControl SOAPmediumCVSS 4.9EPSS 0.3%
- CVE-2026-42058: F5 BIG-IP information leak in iControl RESTmediumCVSS 4.3EPSS 0.2%
- CVE-2026-41954: F5 BIG-IP sensitive information disclosure in iControl REST and tmshmediumCVSS 4.9EPSS 0.3%
- CVE-2026-41953: F5 BIG-IP privilege escalation via configuration object modificationhighCVSS 8.7EPSS 0.3%
- CVE-2026-41225: F5 BIG-IP arbitrary command execution in iControl RESTcriticalCVSS 9.1EPSS 0.3%
- CVE-2026-40631: F5 BIG-IP privilege escalation in iControl SOAPhighCVSS 8.7EPSS 0.3%
- CVE-2026-40618: F5 BIG-IP TMM denial of service in SSL profile processinghighCVSS 7.5EPSS 0.3%
- CVE-2026-40462: F5 BIG-IP incorrect permission assignment in iControl REST and tmshmediumCVSS 6.5EPSS 0.3%
- CVE-2026-40060: F5 BIG-IP Advanced WAF and ASM denial of service in bd processhighCVSS 7.5EPSS 0.3%
- CVE-2026-39459: F5 BIG-IP arbitrary command execution in iControl REST and tmshhighCVSS 7.2EPSS 0.3%
- CVE-2026-35062: F5 BIG-IP information disclosure in iControl SOAP interfacemediumCVSS 6.5EPSS 0.3%
- CVE-2026-34176: F5 BIG-IP command injection in iControl REST Appliance modehighCVSS 8.7EPSS 0.7%
- CVE-2026-32673: F5 BIG-IP privilege escalation in scripted monitorshighCVSS 8.7EPSS 0.2%
- CVE-2026-32643: F5 BIG-IP and BIG-IQ privilege escalation in Certificate Manager rolehighCVSS 8.7EPSS 0.2%
- CVE-2026-24464: F5 BIG-IP directory traversal in iControl REST endpointmediumCVSS 6.8EPSS 0.9%
Most severe F5 BIG-IP Advanced WAF vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-41225: F5 BIG-IP arbitrary command execution in iControl RESTcriticalCVSS 9.1EPSS 0.3%
- CVE-2026-34176: F5 BIG-IP command injection in iControl REST Appliance modehighCVSS 8.7EPSS 0.7%
- CVE-2026-42930: F5 BIG-IP Appliance mode restriction bypass via path traversalhighCVSS 8.7EPSS 0.5%
- CVE-2026-42924: F5 BIG-IP privilege escalation in iControl SOAP via SNMP configurationhighCVSS 8.7EPSS 0.3%
- CVE-2026-41953: F5 BIG-IP privilege escalation via configuration object modificationhighCVSS 8.7EPSS 0.3%
- CVE-2026-40631: F5 BIG-IP privilege escalation in iControl SOAPhighCVSS 8.7EPSS 0.3%
- CVE-2026-32673: F5 BIG-IP privilege escalation in scripted monitorshighCVSS 8.7EPSS 0.2%
- CVE-2026-32643: F5 BIG-IP and BIG-IQ privilege escalation in Certificate Manager rolehighCVSS 8.7EPSS 0.2%
- CVE-2026-40618: F5 BIG-IP TMM denial of service in SSL profile processinghighCVSS 7.5EPSS 0.3%
- CVE-2026-40060: F5 BIG-IP Advanced WAF and ASM denial of service in bd processhighCVSS 7.5EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/big-ip-advanced-waf.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "F5 BIG-IP Advanced WAF vulnerabilities", https://junglewise.ai/threats/technologies/big-ip-advanced-waf, 26 September 2026.