Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY255 SECURITY RECORDS

F5

BIG-IP

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record BIG-IP. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-66842 2 Sep 2026 21.1.0 < 21.1.0.1; 21.0.0 < 21.0.0.3; 17.5.0 < 17.5.1.8; 17.1.0 < 17.1.3.4; 8.4.0 < 8.4.2.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-63020 2 Sep 2026 BIG-IP: 21.1.0 < 21.1.0.1, 21.0.0 < 21.0.0.3, 17.5.0 < 17.5.1.8, 17.1.0 < 17.1.3.4 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-59762 15 Jul 2026 21.1.0 < 21.1.0.1; 21.0.0 < 21.0.0.3; 17.5.0 < 17.5.1.8; 17.1.0 < 17.1.3.4; 2.3.0 < 2.3.2; 2.0.0 < 2.2.3; 1.9.0 < *; 1.7.0 < 1.7.18 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-40423 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-42930 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-24464 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-39458 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-41959 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < *; 8.4.0 < * 21.1.0 < * Update reference ↗
CVE-2026-42406 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < *; 8.4.0 < * 21.1.0 < * Update reference ↗
CVE-2026-42058 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-32643 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < *; 8.4.0 < * 21.1.0 < * Update reference ↗
CVE-2026-42937 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < *; 8.4.0 < * 21.1.0 < * Update reference ↗
CVE-2026-39455 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-32673 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-41217 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-34176 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-42063 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-41225 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-39459 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-41953 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-40631 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-40698 13 May 2026 21.0.0 < 21.0.0.2; 17.5.0 < 17.5.1.6; 17.1.0 < 17.1.3.2; 16.1.0 < *; 8.4.0 < * 21.1.0 < * Update reference ↗
CVE-2026-42924 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-40060 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-42409 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < *; 2.0.0 < 2.0.3; 1.7.0 < 1.7.17; 1.4.0 < 1.4.1; 2.0.0 < 2.1.1 21.1.0 < * Update reference ↗
CVE-2026-41227 13 May 2026 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.0.0 < * Update reference ↗
CVE-2026-40061 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-35062 13 May 2026 21.0.0 < 21.0.0.1; 17.5.1 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-40618 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.1.5.4; 17.1.0 < 17.1.3.1; 16.1.0 < *; 2.0.0 < *; 1.7.0 < *; 1.1.0 < *; 2.0.0 < 2.2.0 21.1.0 < * Update reference ↗
CVE-2026-41956 13 May 2026 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < *; 2.0.0 < 2.0.3; 1.4.0 < 1.4.1; 2.0.0 < 2.1.0 21.0.0 < *; 2.1.0 < * Update reference ↗
CVE-2026-42920 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-40629 13 May 2026 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < *; 2.0.0 < 2.0.3; 1.7.0 < 1.7.16; 1.1.0 < 1.4.1; 2.0.0 < 2.1.1 21.0.0 < * Update reference ↗
CVE-2026-42919 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-41218 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-42781 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1 21.1.0 < *; 16.1.0 < * Update reference ↗
CVE-2026-41957 13 May 2026 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < *; 8.4.0 < 8.4.1 21.0.0 < * Update reference ↗
CVE-2026-42408 13 May 2026 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.0.0 < * Update reference ↗
CVE-2026-40067 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-40699 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-34019 13 May 2026 17.5.0 < 17.5.1; 17.1.0 < 17.1.3; 16.1.0 < * 21.0.0 < * Update reference ↗
CVE-2026-42780 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.5; 17.1.0 < 17.1.3.1; 16.1.0 < *; 13.0 < 13.1.3; 12.0 < 12.3.2; 11.0 < 11.4.1 21.1.0 < *; 14.0 < * Update reference ↗
CVE-2026-41219 13 May 2026 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < *; 8.4.0 < 8.4.1 21.0.0 < * Update reference ↗
CVE-2026-40462 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.1.0 < * Update reference ↗
CVE-2026-28758 13 May 2026 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.0.0 < * Update reference ↗
CVE-2026-41954 13 May 2026 21.0.0 < 21.0.0.1; 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < *; 8.4.0 < 8.4.1 21.1.0 < * Update reference ↗
CVE-2026-40435 13 May 2026 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.0.0 < * Update reference ↗
CVE-2026-40703 13 May 2026 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.0.0 < * Update reference ↗
CVE-2026-2507 18 Feb 2026 17.5.1.4 < * 21.0.0 < *; 17.1.0 < *; 16.1.0 < * Update reference ↗
CVE-2026-22548 4 Feb 2026 17.1.0 < 17.1.3 21.0.0 < *; 17.5.0 < *; 16.1.0 < * Update reference ↗
CVE-2026-20732 4 Feb 2026 17.5.0 < 17.5.1.4; 17.1.0 < 17.1.3.1; 16.1.0 < * 21.0.0 < * Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.