VENDOR

F5 vulnerabilities: CVEs, exploitation and patches

Every F5 CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-42533
    NGINX Plus heap buffer overflow with regex map leading to remote code execution F5 NGINX Plus ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.1
  2. CVE-2026-94127
    BIG-IP APM heap buffer overflow remote code execution F5 BIG-IP APM ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
2 CVEs · page 1 of 1