VulnSea

f5 has 9 CVEs on record. Disclosures have slowed: 2 in the last 90 days after 7 in the 90 before. The busiest recent month was June 2026 with 4. The median CVSS is 8.1 (high). None have a confirmed exploitation report. The most common weakness class is CWE-122 (4). Most affected products: nginx_gateway_fabric (3), big-ip_access_policy_manager (2), dos (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.1
Publish → KEV
Last 90 days
2 prev 7

Products

  • nginx_gateway_fabric 3
  • big-ip_access_policy_manager 2
  • dos 2
  • NGINX Plus 1
  • njs 1
9
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

f5 vulnerabilities

CVEs affecting f5, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-90439Medium· 6.5
1w ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a…

SunlitF5 · NGINX PlusEPSS 0.26%via NVD
CVE-2026-63020Low· 3.1
2w ago

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages  Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a …

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages  Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a …

Sunlitf5 · big-ip_access_policy_managerEPSS 0.19%via NVD
CVE-2026-32682Medium· 6.5
3mo ago

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPC…

When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or modify GRPCRoute resources can cause the NGINX Gateway Fabric control plane to terminate by sending undisclosed GRPC…

Sunlitf5 · nginx_gateway_fabricEPSS 0.29%via NVD
CVE-2026-42530High· 8.1PoC
3mo ago

NGINX Open Source has a vulnerability in the ngx_http_v3_module module

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially …

Midnightf5 · nginx_gateway_fabricEPSS 3.8%via NVD
CVE-2026-42055High· 8.1PoC
3mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, …

Midnightf5 · dosEPSS 6.5%via NVD
CVE-2026-11311High· 8.1
3mo ago

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Re…

Twilightf5 · nginx_gateway_fabricEPSS 0.57%via NVD
CVE-2026-8711High· 8.1
4mo ago

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGIN…

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGIN…

Twilightf5 · njsEPSS 9.7%via NVD
CVE-2026-42945High· 8.1PoC
4mo ago

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expre…

Midnightf5 · dosEPSS 68%via NVD
CVE-2026-40698High· 8.7
4mo ago

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resu…

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can create SNMP configuration objects through iControl REST or the TMOS shell (tmsh) resu…

Twilightf5 · big-ip_access_policy_managerEPSS 0.24%via NVD
f5 vulnerabilities (CVEs) · VulnSea