2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41218HIGH8.7When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIF...
CVE-2026-41217HIGH8.3A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with ...
CVE-2026-40703MEDIUM5.4A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility.  Note: So...
CVE-2026-40701MEDIUM6.3NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client direc...
CVE-2026-40699HIGH7.1A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticat...
CVE-2026-40698HIGH8.7A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the ...
CVE-2026-40631HIGH8.7An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through...
CVE-2026-40629HIGH8.7When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processin...
CVE-2026-40618HIGH8.7When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technolog...
CVE-2026-40462HIGH7.1Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which m...
CVE-2026-40460MEDIUM6.9When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof thei...
CVE-2026-40435MEDIUM6.9When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blo...
CVE-2026-40423HIGH8.7When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (...
CVE-2026-40067HIGH8.7When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to ter...
CVE-2026-40061HIGH8.7When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) comm...
CVE-2026-40060HIGH8.7When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the ...
CVE-2026-39459HIGH8.6A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with...
CVE-2026-39458HIGH7.5When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WA...
CVE-2026-39455HIGH8.7When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, ...
CVE-2026-36742MEDIUM6.8Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected...
CVE-2026-36741HIGH7.2U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol ...
CVE-2026-36738MEDIUM6.8U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes ...
CVE-2026-35062HIGH7.1An authenticated iControl SOAP user may be able to obtain information of other accounts.  Note: Software versions which...
CVE-2026-34176HIGH8.7When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iContro...
CVE-2026-34019MEDIUM6.3When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now