Vendor
F5 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 82 vulnerabilities in F5: 1 in the last 7 days and 11 in the last 90 days, 12 of them critical and 11 exploited in the wild. The most recent, CVE-2026-94127, was published on 22 September 2026. 14 technologies have a page of their own.
- Last 7 days
- 1
- Last 90 days
- 11
- Critical, all time
- 12
- Exploited in the wild
- 11
About F5
Company that develops application delivery and security software.
F5 technologies
- F5 BIG-IP41
- F5 BIG-IP Access Policy Manager30
- F5 BIG-IP Advanced Firewall Manager28
- F5 BIG-IP Local Traffic Manager27
- F5 BIG-IP Advanced WAF19
- F5 NGINX Plus14
- F5 Nginx-Gateway-Fabric8
- F5 NGINX Ingress Controller8
- F5 BIG-IQ7
- F5 BIG-IP DNS6
- F5 BIG-IQ Centralized Management4
- F5 BIG-IP APM3
- F5 iControl REST3
- F5 NGINX Instance Manager3
Latest F5 vulnerabilities
- CVE-2026-94127: When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can…criticalexploited in the wildCVSS 9.8EPSS 2.2%
- CVE-2026-66842: F5 BIG-IP privilege escalation in TMUIhighCVSS 8.8EPSS 0.5%
- CVE-2026-63020: F5 BIG-IP Configuration utility error message spoofinglowCVSS 3.1EPSS 0.2%
- CVE-2026-60005: NGINX uninitialized memory access in ngx_http_slice_modulehighCVSS 8.2
- CVE-2026-60065: F5 NGINX Plus heap buffer over-read in MQTT filter modulelowCVSS 3.7
- CVE-2026-60062: F5 NGINX Agent path traversal in config_dirs directivemediumCVSS 6.4
- CVE-2026-59762: F5 BIG-IP denial of service in HTTP/2 profile memory managementhighCVSS 7.5
- CVE-2026-56434: F5 NGINX heap buffer over-read in ngx_http_ssi_modulemediumCVSS 6.5
- CVE-2026-55723: F5 NGINX Ingress Controller configuration injection in CRDs and annotationshighCVSS 8.3
- CVE-2026-52865: F5 NGINX Ingress Controller NULL pointer dereference in Ingress resourcesmediumCVSS 6.5
- CVE-2026-42533: F5 NGINX heap buffer overflow in map directivehighCVSS 8.1
- CVE-2026-50107: F5 NGINX Gateway Fabric configuration injection in NginxProxy CRDhighCVSS 8.1EPSS 0.3%
- CVE-2026-32682: F5 NGINX Gateway Fabric DoS in GRPCRoute backendRef filtersmediumCVSS 6.5EPSS 0.3%
- CVE-2026-48142: F5 NGINX heap buffer over-read in ngx_http_charset_modulemediumCVSS 4.8EPSS 0.4%
- CVE-2026-42055: NGINX heap buffer overflow in HTTP/2 and gRPC proxy moduleshighCVSS 8.1EPSS 0.6%
- CVE-2026-11311: F5 NGINX Gateway Fabric configuration injection in CRD fieldshighCVSS 8.1EPSS 0.4%
- CVE-2026-9256: F5 NGINX heap buffer overflow in ngx_http_rewrite_modulehighCVSS 8.1EPSS 0.9%
- CVE-2026-8711: F5 NGINX JavaScript heap buffer overflow in js_fetch_proxyhighCVSS 8.1
- CVE-2026-42946: F5 NGINX memory over-read in SCGI and uWSGI modulesmediumCVSS 6.5EPSS 0.8%
- CVE-2026-42945: NGINX heap buffer overflow in ngx_http_rewrite_modulehighCVSS 8.1EPSS 0.3%
- CVE-2026-42937: F5 BIG-IP and BIG-IQ incorrect permission assignment in tmsh and iControl RESTmediumCVSS 6.5EPSS 0.2%
- CVE-2026-42934: F5 NGINX heap buffer over-read in ngx_http_charset_modulemediumCVSS 4.8EPSS 0.7%
- CVE-2026-42930: F5 BIG-IP Appliance mode restriction bypass via path traversalhighCVSS 8.7EPSS 0.5%
- CVE-2026-42926: F5 NGINX Open Source header injection in HTTP/2 proxyingmediumCVSS 5.8EPSS 0.3%
- CVE-2026-42924: F5 BIG-IP privilege escalation in iControl SOAP via SNMP configurationhighCVSS 8.7EPSS 0.3%
Most severe F5 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-53521: F5 BIG-IP stack-based buffer overflow in APMcriticalexploited in the wildCVSS 9.8EPSS 7.4%
- CVE-2026-94127: When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can…criticalexploited in the wildCVSS 9.8EPSS 2.2%
- CVE-2023-46747: F5 BIG-IP Configuration Utility Authentication Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2022-1388: F5 BIG-IP Missing Authentication Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2021-22991: F5 BIG-IP Traffic Management Microkernel Buffer Overflowcriticalexploited in the wildCVSS 9.8
- CVE-2021-22986: F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2020-5902: F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-46748: F5 BIG-IP Configuration Utility SQL Injection Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2018-14634: Linux Kernel integer overflow in create_elf_tablescriticalexploited in the wildCVSS 7.8EPSS 24.1%
- CVE-2023-44487: HTTP/2 Rapid Reset Attack Vulnerabilitycriticalexploited in the wildCVSS 7.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 8 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 1 | 1 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/f5.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "F5 vulnerabilities", https://junglewise.ai/threats/vendors/f5, 26 September 2026.