8.7
CVE-2025-53856 - TMM vulnerability
When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object uses the embedded Packet Velocity Acceleration (ePVA) feature, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.ย To determine which BIG-IP platforโฆ
8.7
CVE-2025-54479 - BIG-IP PEM vulnerability
When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
7.7
CVE-2025-59778 - VELOS partition container network vulnerability
When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause multiple containers to terminate.ย ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
6
CVE-2025-54805 - TMM Vulnerability
When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization.ย Note: Software versions which have reached End of Technical Support (EoTS) are not evalโฆ
7.1
CVE-2025-55670 - BIG-IP Next (CNF, SPK, and Kubernetes) vulnerability
On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate.ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
8.7
CVE-2025-41430 - BIG-IP SSL Orchestrator vulnerability
When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
8.7
CVE-2025-61938 - BIG-IP Advanced WAF and ASM bd process vulnerability
When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process can terminate repeatedly.ย ย Note: Software versions which have โฆ
6.3
CVE-2025-58424 - BIG-IP TMM vulnerability
On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data modification in protocols which do not have message integrity protection.ย ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
8.7
CVE-2025-55036 - BIG-IP SSL Orchestrator vulnerability
When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is enabled, undisclosed traffic may cause memory corruption.ย ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
8.7
CVE-2025-59781 - BIG-IP DNS cache vulnerability
When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increase in memory resource utilization.ย ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.