F5 Products Multiple Vulnerabilities
CSIRTS triage
- What
- Multiple vulnerabilities exist in F5 products.
- Who is affected
- Deployments of various F5 products are affected.
- Urgency
- Remediation urgency is unclear due to unknown severity and no exploitation reported.
- Action
- Check for updates from F5 regarding these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.hkcert.org/security-bulletin/f5-products-multiple-vulnerabilities_20260729
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation likely imminentCVE-2025-48976EPSS puts this in the most-targeted tier (67.3% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99% of all scored CVEs.
- Low exploitation riskCVE-2025-664180.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all scored CVEs.
- Low exploitation riskCVE-2026-64740.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-66370.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-48976 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-66418 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6474 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6637 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] PostgreSQL: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Red Hat Enterprise Linux (urllib3): Multiple vulnerabilities allow denial of servicecert-bund
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Red Hat OpenShift and OpenShift AI (urllib3): Vulnerability allows denial of servicecert-bund
- high[UPDATE] [high] IBM QRadar SIEM: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Commerce: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Tenable Security Center (July 21, 2026)cert-fr-avis
- high[UPDATE] [high] Dell PowerProtect Data Domain OS: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in IBM products (July 10, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Stormshield Management Center (June 29, 2026)cert-fr-avis
More from HKCERT Security Bulletins
- unknownCisco Secure Firewall Management Center Software Information Disclosure Vulnerability2026-07-30
- unknownGoogle Chrome Multiple Vulnerabilities2026-07-30
- unknownIBM WebSphere Products Multiple Vulnerabilities2026-07-30
- unknownNode.js Multiple Vulnerabilities2026-07-30
- unknownXen Multiple Vulnerabilities2026-07-30