|
1301
|
7.9 |
HIGH
Local
|
-
|
-
|
A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system comman…
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-41217
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1302
|
7.5 |
HIGH
Network
|
-
|
-
|
When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause …
New
|
CWE-416
Use After Free
|
CVE-2026-41218
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1303
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file.
Note: Software versions which ha…
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-41219
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1304
|
9.1 |
CRITICAL
Network
|
-
|
-
|
A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.
Note…
New
|
CWE-648
Incorrect Use of Privileged APIs
|
CVE-2026-41225
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1305
|
7.5 |
HIGH
Network
|
-
|
-
|
On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to ter…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-41227
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1306
|
8.7 |
HIGH
Network
|
-
|
-
|
A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escala…
New
|
CWE-77
Command Injection
|
CVE-2026-41953
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1307
|
4.9 |
MEDIUM
Network
|
-
|
-
|
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator rol…
New
|
CWE-200
Information Exposure
|
CVE-2026-41954
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1308
|
7.5 |
HIGH
Network
|
-
|
-
|
When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached …
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-41956
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1309
|
8.8 |
HIGH
Network
|
-
|
-
|
An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.
Note: Software versions which have reached End of Technical S…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-41957
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1310
|
6.5 |
MEDIUM
Local
|
-
|
-
|
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated…
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-41959
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|