BIG-IP Access Policy Manager Client
20 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for BIG-IP Access Policy Manager Client, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
BIG-IP Access Policy Manager Client CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 20 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High10
- Medium8
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting BIG-IP Access Policy Manager Client.
- CVE-2026-20730BIG-IP Edge Client for Windows vulnerability3.3
- CVE-2025-48500BIG-IP APM VPN web client for macOS vulnerability7.3
- CVE-2024-28883BIG-IP APM browser network access VPN client vulnerability7.4
- CVE-2023-43125BIG-IP APM Clients TunnelCrack vulnerability6.8
- CVE-2023-43124BIG-IP APM Clients TunnelCrack vulnerability5.3
- CVE-2022-28714On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as ...7.3
- CVE-2022-27636On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as ...5.5
- CVE-2022-23032In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system, connecting BIG-IP Edge Client on Mac and Windows is vulnerable to a DNS reb...5.3
- CVE-2021-23022On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak file and folder permissions. Note: Software version...7.8
- CVE-2020-5898In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user on the Windows client system can send crafted DeviceIoCon...5.5
- CVE-2020-5896On versions 7.1.5-7.1.9, the BIG-IP Edge Client's Windows Installer Service's temporary folder has weak file and folder permissions.7.8
- CVE-2020-5897In versions 7.1.5-7.1.9, there is use-after-free memory vulnerability in the BIG-IP Edge Client Windows ActiveX component.8.8
- CVE-2020-5892In versions 7.1.5-7.1.8, the BIG-IP Edge Client components in BIG-IP APM, Edge Gateway, and FirePass legacy allow attackers to obtain the full session ID from process memory.6.7
- CVE-2020-5893In versions 7.1.5-7.1.8, when a user connects to a VPN using BIG-IP Edge Client over an unsecure network, BIG-IP Edge Client responds to authentication requests over HTTP while sending probes for c...3.7
- CVE-2020-5855When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorized users who have physical access to an authorized user's machine can get shel...4.3
Product grouping is registry-driven, with AI assist and human review. How it works