Big Ip
Vendor:
First CVE: Feb 19, 2008 · Active for 18 years
128
Total CVEs
More Total CVEs than 99% of tracked products
16.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.8%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Big Ip over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 19, 2008
18 years ago
Most Recent CVE
May 13, 2026
72 days ago
CVE Severity & Scoring
Big Ip128 CVEs
32%
64%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (5.5%)
Network116 (90.6%)
Unknown3 (2.3%)
Physical1 (0.8%)
Adjacent Network1 (0.8%)
Attack Complexity
Low117 (91.4%)
High8 (6.3%)
Unknown3 (2.3%)
User Interaction
None112 (87.5%)
Unknown3 (2.3%)
Required13 (10.2%)
Privileges Required
Low16 (12.5%)
High31 (24.2%)
None78 (60.9%)
Unknown3 (2.3%)
Top CVEs
Signals from CVEs in this product scope (128 CVEs).
128 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-53521CRITICAL When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).
Note: Software versions which have reached | Oct 15, 2025 | 9.8 | 80 | YES | NO |
CVE-2023-22374HIGH
A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appli | Feb 1, 2023 | 8.5 | 67 | NO | NO |
CVE-2007-6258HIGH Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) | Feb 19, 2008 | 7.5 | 54 | NO | YES |
CVE-2025-31644HIGH When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attac | May 7, 2025 | 8.7 | 43 | NO | NO |
CVE-2026-41225CRITICAL A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitra | May 13, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-41953HIGH A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting | May 13, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-40631HIGH An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through iControl SOAP resulting in privilege escalation. Note: Sof | May 13, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-40061HIGH When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resour | May 13, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-34176HIGH When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker | May 13, 2026 | 8.7 | 34 | NO | NO |
CVE-2026-32673HIGH A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system comman | May 13, 2026 | 8.7 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (128 CVEs).
CISA KEV
1 CVE
0.8% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.6% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (128 CVEs).
Media Mentions
Signals from CVEs in this product scope (128 CVEs).
Top CNAs Publishing CVEs For Big Ip
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.4.3 | 1 | 6.8 | 2.4% | 0 | 1 |
| 9.2.3.30 | 1 | 7.5 | 41.5% | 0 | 1 |
| 11.3.0 | 1 | 4.3 | 2.1% | 0 | 0 |