boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

F5

Vendor reference — F5 · sector: Network & Infrastructure. Cumulative disclosure record across the archive.

Follow F5 — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs2317
KEV entries71
Rate & severity
KEV/100Med CVSSMed EPSSCHML
30.48.6.02215830

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▃▁▂▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▃▆█▁

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-031
2026-040
2026-052
2026-066
2026-078
2026-080

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2020-5902100.0YES2021-11-03
CVE-2022-1388100.0YES2022-05-10
CVE-2021-22986100.0YES2021-11-03
CVE-2023-4674799.9YES2023-10-31
CVE-2021-2299199.1YES2022-01-18
CVE-2023-4674890.7YES2023-10-31
CVE-2025-5352181.2YES2026-03-27
CVE-2026-429459.299.2CRITICAL2026-05-13
CVE-2026-92569.295.2CRITICAL2026-05-22
CVE-2026-420559.289.7CRITICAL2026-06-17
CVE-2026-425309.288.8CRITICAL2026-06-17
CVE-2026-425339.288.2CRITICAL2026-07-15
CVE-2026-600058.850.7HIGH2026-07-15
CVE-2026-481426.349.8MEDIUM2026-06-17
CVE-2026-113118.644.5HIGH2026-06-17

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-600656.318.5MEDIUM2026-07-15
CVE-2026-600625.310.4MEDIUM2026-07-15
CVE-2026-600058.850.7HIGH2026-07-15
CVE-2026-597628.738.2HIGH2026-07-15
CVE-2026-564348.337.6HIGH2026-07-15
CVE-2026-557238.721.9HIGH2026-07-15
CVE-2026-528657.121.2HIGH2026-07-15
CVE-2026-425339.288.2CRITICAL2026-07-15
CVE-2026-501078.640.3HIGH2026-06-17
CVE-2026-481426.349.8MEDIUM2026-06-17
CVE-2026-425309.288.8CRITICAL2026-06-17
CVE-2026-420559.289.7CRITICAL2026-06-17
CVE-2026-326827.121.8HIGH2026-06-17
CVE-2026-113118.644.5HIGH2026-06-17
CVE-2026-92569.295.2CRITICAL2026-05-22

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
NGINX Open Source80
NGINX Plus80
BIG-IP43
NGINX Gateway Fabric30
BIG-IP Configuration Utility22
NGINX Ingress Controller20

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2025-535212026-03-2781.2
CVE-2023-467472023-10-3199.9
CVE-2023-467482023-10-3190.7
CVE-2022-13882022-05-10100.0
CVE-2021-229912022-01-1899.1
CVE-2021-229862021-11-03100.0
CVE-2020-59022021-11-03100.0

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2021-229862021-11-171736
CVE-2021-229912022-02-011660
CVE-2020-59022022-05-031569
CVE-2022-13882022-05-311541
CVE-2023-467482023-11-211002
CVE-2023-467472023-11-211002
CVE-2025-535212026-03-30142

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.