<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — F5</title><description>Vulnerabilities in F5 BIG-IP&apos;s iControl REST and TMUI management interfaces — application-delivery controllers whose compromise typically hands attackers control of the load-balanced traffic behind them. Combined article + CVE feed for the F5 beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2020-5902 — F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2020-5902/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-5902/</guid><description>F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>F5</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-22986 — F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-22986/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-22986/</guid><description>F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>F5</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-22991 — F5 BIG-IP Traffic Management Microkernel Buffer Overflow</title><link>https://0daynews.com/cve/cve-2021-22991/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-22991/</guid><description>The Traffic Management Microkernel of BIG-IP ASM Risk Engine has a buffer overflow vulnerability, leading to a bypassing of URL-based access controls.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>F5</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-1388 — F5 BIG-IP iControl REST Authentication Bypass</title><link>https://0daynews.com/cve/cve-2022-1388/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-1388/</guid><description>An authentication-bypass vulnerability in the F5 BIG-IP iControl REST API allows an unauthenticated attacker with network access to the management interface or self-IP addresses to execute arbitrary system commands, create or delete files, or disable services.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>F5</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-46747 — F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2023-46747/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-46747/</guid><description>F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>F5</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-46748 — F5 BIG-IP Configuration Utility SQL Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2023-46748/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-46748/</guid><description>F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>F5</category><category>high</category><category>cve</category></item><item><title>CVE-2025-53521 — F5 BIG-IP Stack-Based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2025-53521/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-53521/</guid><description>F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>F5</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-42533 — nginx map directive regex-capture heap buffer overflow in worker</title><link>https://0daynews.com/cve/cve-2026-42533/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-42533/</guid><description>A heap buffer overflow in the nginx worker process when a map directive&apos;s string expression references its regex capture variables before the output variable. Reachable via crafted HTTP; DoS by worker restart, code execution possible only where ASLR is disabled or bypassable.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>F5</category><category>high</category><category>cve</category></item><item><title>F5 BIG-IP&apos;s Max-Severity Auth Bypass, Explained</title><link>https://0daynews.com/articles/2026-07-02-f5-big-ip-icontrol-rest-auth-bypass/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-02-f5-big-ip-icontrol-rest-auth-bypass/</guid><description>A critical authentication-bypass flaw in F5 BIG-IP&apos;s iControl REST API let unauthenticated attackers execute system commands on appliances that front an enormous share of enterprise application traffic.</description><pubDate>Thu, 02 Jul 2026 15:00:00 GMT</pubDate><category>F5</category><category>article</category></item></channel></rss>