F5, Inc.

First CVE: Jan 3, 2017Active for: 10 years
816
CVEs Published
More CVEs Published than 90% of tracked CNAs
81.6
Avg CVEs / Year
More Avg CVEs / Year than 88% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked CNAs
0.9%
In CISA KEV
Higher KEV Rate than 87% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by F5, Inc. as a CNA, 99.3% affect products that F5, Inc. develops as a vendor.

99.3%
Self-reported: 810Third-party: 6

Of all the CVEs published that affect products developed by F5, Inc., 78.5% are self-published by F5, Inc. as a CNA.

78.5%
21.5%
Self-published: 810Published by other CNAs: 222

Trends Over Time

The number and severity of CVEs published by F5, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 3, 2017
9 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Top CVEs

All CVEs published by F5, Inc. as a CNA, regardless of affected vendor or product.

816 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x ver
May 5, 20229.899YESYES
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.
Mar 31, 20219.899YESYES
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Co
Jul 1, 20209.899YESYES
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addre
Oct 26, 20239.898YESYES
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclosed requests to a virtual serve
Mar 31, 20219.890YESNO
In all versions,  BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.   Note: Software versions which have reached End of Technic
Dec 7, 20228.884NOYES
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached
Oct 15, 20259.880YESNO
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an un
Dec 7, 20228.780NOYES
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or s
May 13, 20268.179NONO
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attac
Feb 9, 20177.576NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA816 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local88 (10.8%)
Network710 (87.0%)
Unknown0 (0.0%)
Physical3 (0.4%)
Adjacent Network15 (1.8%)
Attack Complexity
Low709 (86.9%)
High107 (13.1%)
Unknown0 (0.0%)
User Interaction
None719 (88.1%)
Unknown0 (0.0%)
Required97 (11.9%)
Privileges Required
Low166 (20.3%)
High112 (13.7%)
None538 (65.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (816 CVEs).

CISA KEV
7 CVEs
0.9% of CVEs· 87th percentile
Metasploit
7 CVEs
0.9% of CVEs· 86th percentile
Nuclei
5 CVEs
0.6% of CVEs· 77th percentile
ExploitDB
6 CVEs
0.7% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by F5, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by F5, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs