F5
F5 Big-ip Next Cloud-native Network Functions: vulnerabilities and CVEs
F5 Big-ip Next Cloud-native Network Functions has 27 published vulnerabilities, 16 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs27
Last 12 months16
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59762 | High (8.7) | 0.57% | — | Jul 15, 2026 | When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to… |
| CVE-2026-42409 | High (8.7) | 0.46% | — | May 13, 2026 | When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to… |
| CVE-2026-41956 | High (8.7) | 0.46% | — | May 13, 2026 | When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical… |
| CVE-2026-40629 | High (8.7) | 0.46% | — | May 13, 2026 | When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support… |
| CVE-2026-40618 | High (8.7) | 0.46% | — | May 13, 2026 | When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to… |
| CVE-2025-61990 | High (8.7) | 0.35% | — | Oct 15, 2025 | When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support… |
| CVE-2025-58071 | High (8.7) | 0.37% | — | Oct 15, 2025 | When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not… |
| CVE-2025-61974 | High (8.7) | 0.46% | — | Oct 15, 2025 | When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not… |
| CVE-2025-60016 | High (8.7) | 0.44% | — | Oct 15, 2025 | When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cipher Rule or Cipher Group, and that profile is applied to a virtual server, undisclosed traffic can… |
| CVE-2025-59781 | High (8.7) | 0.35% | — | Oct 15, 2025 | When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical… |
| CVE-2025-58120 | High (8.7) | 0.35% | — | Oct 15, 2025 | When HTTP/2 Ingress is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
| CVE-2025-55670 | High (7.1) | 0.31% | — | Oct 15, 2025 | On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End… |
| CVE-2025-54805 | Medium (6) | 0.31% | — | Oct 15, 2025 | When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization. Note:… |
| CVE-2025-54479 | High (8.7) | 0.35% | — | Oct 15, 2025 | When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have… |
| CVE-2025-48008 | High (8.7) | 0.44% | — | Oct 15, 2025 | When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to… |
| CVE-2025-46706 | High (8.7) | 0.43% | — | Oct 15, 2025 | When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of… |
| CVE-2025-54500 | Medium (6.9) | 0.50% | — | Aug 13, 2025 | An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which… |
| CVE-2025-41414 | High (8.7) | 0.41% | — | May 7, 2025 | When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |
| CVE-2025-41399 | High (8.7) | 0.41% | — | May 7, 2025 | When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of… |
| CVE-2025-36557 | High (8.7) | 0.41% | — | May 7, 2025 | When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have… |
| CVE-2025-36504 | High (8.7) | 0.42% | — | May 7, 2025 | When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support… |
| CVE-2025-24312 | High (8.7) | 0.40% | — | Feb 5, 2025 | When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, undisclosed traffic can cause an increase in CPU resource utilization.… |
| CVE-2024-41164 | High (8.2) | 0.44% | — | Aug 14, 2024 | When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which… |
| CVE-2024-28132 | Medium (4.4) | 0.17% | — | May 8, 2024 | Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an authenticated attacker with local access to view sensitive information. Note: Software versions which have reached End of… |
| CVE-2024-25560 | High (7.5) | 0.52% | — | May 8, 2024 | When BIG-IP AFM is licensed and provisioned, undisclosed DNS traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not… |
| CVE-2024-23306 | High (7.1) | 0.15% | — | Feb 14, 2024 | A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |
| CVE-2023-45886 | High (7.5) | 1.4% | — | Nov 21, 2023 | The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute. |
Other products by F5
Big-ip Access Policy Manager · 630Big-ip Application Security Manager · 581Big-ip Advanced Firewall Manager · 552Big-ip Local Traffic Manager · 541Big-ip Policy Enforcement Manager · 533Big-ip Link Controller · 525Big-ip Application Acceleration Manager · 524Big-ip Analytics · 511Big-ip Global Traffic Manager · 490Big-ip Domain Name System · 469Big-ip Fraud Protection Service · 405Big-ip Webaccelerator · 297