|
2171
|
7.5 |
HIGH
Network
|
-
|
-
|
When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, and the urlcatquery command), undisclosed traffic can cause …
|
CWE-416
Use After Free
|
CVE-2026-41218
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2172
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file.
Note: Software versions which ha…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-41219
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2173
|
9.1 |
CRITICAL
Network
|
-
|
-
|
A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.
Note…
|
CWE-648
Incorrect Use of Privileged APIs
|
CVE-2026-41225
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2174
|
7.5 |
HIGH
Network
|
-
|
-
|
On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to ter…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-41227
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2175
|
8.7 |
HIGH
Network
|
-
|
-
|
A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escala…
|
CWE-77
Command Injection
|
CVE-2026-41953
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2176
|
4.9 |
MEDIUM
Network
|
-
|
-
|
Sensitive information disclosure vulnerability exists in the undisclosed iControl REST endpoint and TMOS Shell (tmsh) command which may allow an authenticated attacker with resource administrator rol…
|
CWE-200
Information Exposure
|
CVE-2026-41954
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2177
|
7.5 |
HIGH
Network
|
-
|
-
|
When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached …
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-41956
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2178
|
8.8 |
HIGH
Network
|
-
|
-
|
An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.
Note: Software versions which have reached End of Technical S…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-41957
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2179
|
6.5 |
MEDIUM
Local
|
-
|
-
|
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-41959
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2180
|
4.3 |
MEDIUM
Network
|
-
|
-
|
An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local user account names. Note: Software versions which have reached End of Technic…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-42058
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|