Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/f5networks/BIG-IP

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-42930 is a high-severity vulnerability in F5 BIG-IP systems running in Appliance mode. It allows an authenticated attacker with the 'Administrator' role to bypass Appliance mode restrictions by exploiting a path traversal issue (CWE-35). This vulnerability affects multiple BIG-IP versions including 21.0.0, 17.5.0, 17.1.0, and 16.1.

Join the discussion

An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local user account names.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Join the discussion

When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Join the discussion

CVE-2026-41225 is a high-severity vulnerability in F5 BIG-IP's iControl REST interface. It allows a highly privileged, authenticated attacker with at least Manager role permissions to create configuration objects that enable execution of arbitrary commands. This vulnerability affects specific versions of BIG-IP including 21.0.0, 17.5.0, 17.1.0, and 16.1.

Join the discussion

CVE-2026-39459 is a high-severity vulnerability in F5 BIG-IP affecting iControl REST and TMOS Shell (tmsh). It allows a highly privileged, authenticated attacker with at least the Manager role to create configuration objects that enable running arbitrary commands. This violates the principle of least privilege and could lead to full system compromise. The affected versions include 16.1.0, 17.1.0, 17.5.0, and 21.

Join the discussion

CVE-2026-40698 is a high-severity OS command injection vulnerability in F5 BIG-IP and BIG-IQ systems. It allows a highly privileged, authenticated attacker with at least Resource Administrator role to create SNMP configuration objects via iControl REST or TMOS shell (tmsh), leading to privilege escalation. The vulnerability affects specific versions including 21.0.0, 17.5.0, 17.1.0, and 16.1.

Join the discussion

CVE-2026-42924 is a high-severity vulnerability in F5 BIG-IP affecting versions 16.1.0, 17.1.0, 17.5.0, and 21.0.0. It allows an authenticated attacker with Resource Administrator or Administrator roles to create SNMP configuration objects via the iControl SOAP interface, resulting in privilege escalation.

Join the discussion

CVE-2026-40061 is a command injection vulnerability in F5 BIG-IP DNS when provisioned, affecting certain versions. It allows an authenticated user with Resource Administrator or Administrator roles to execute arbitrary system commands with elevated privileges. In Appliance mode deployments, exploitation can cross a security boundary. The vulnerability has a CVSS score of 6.5, indicating medium severity. No official patch or remediation level has been provided yet, and no known exploits are reported in the wild.

Join the discussion

When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Join the discussion

When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Join the discussion

Showing 1 to 10 of 20 results

Filters:Package: pkg:github/f5networks/BIG-IP
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses