CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026
Evidence dossier
CVE-2021-22986
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3…
Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 9.8. EPSS estimates 99.9% exploit likelihood as of Aug 6, 2026.
As of Aug 27, 2026
Normalized restatement
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
- State
- PUBLISHED
- Published
- Mar 31, 2021
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAf5Original evidence ↗
Record text: On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Inspect raw assertion
- Field
container- Value
- On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 99.9% probability · 99.97th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.998980000000; percentile 0.999650000000
FIRST EPSS · score date Aug 6, 2026 · 100th percentile · first observed Aug 6, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
Inspect raw assertion
- Field
container- Value
- On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2, the iControl REST interface has an unauthenticated remote command execution vulnerability. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.
F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
99.9% probability · 99.97th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.998980000000; percentile 0.999650000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
16 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "BIG-IP 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3"}, {"status": "affected", "version": "BIG-IQ 7.1.0.x before 7.1.0.3, 7.0.0.x before 7.0.0.2"}]product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cbLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
8c3a0a32-e425-4939-a30d-95a046abbabb
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
14de89cf-f8ee-4e09-9755-81f9a2f44f85
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
fb553a20-d521-4a32-ad49-8ffd5a95e684
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
a7706f70-bf89-480e-9aa6-3fe447375138
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
6ed8c663-038b-4071-9ff9-ae609f2da4cd
product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
f76ed86b-7c48-4921-af97-68307c181e7d
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
f0ac967d-8d6d-44f5-88ef-a50f18979774
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
fe73e240-2cb5-40cb-8e58-08989f5d0156
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
0a84a8d4-9047-46d2-9c26-03c977d47ae4
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
dd3fc6d2-5816-47c0-81ae-ded62570f090
product-3159127811fadcfbf55e58810b397c704a5ecb216e89a6fccc26cab6944674c7Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
61ba4596-efd4-483f-952d-4298b6cefa9d
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
db183373-a897-43df-a544-364e59358f30
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
39dda652-065c-4af9-a014-e0daff60b61b
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
12a27d41-6dec-4887-a9a0-fe5aad01fa98
cpe:2.3:a:f5:big-ip_advanced_web_application_firewall:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
6b9117da-6aa9-4704-a092-b1d426e6370d
product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943fLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
f2442894-a473-49a5-95b6-6312c3407fe6
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
4ae6833c-ff7c-4249-bf98-453645eef8d9
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
b462a70a-2504-4e8c-85c3-d771cdb34038
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
c33ff2cf-2b91-489d-bd48-0cf9b7f0b8a1
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
6b8ab156-1960-4220-8fd2-bf7fbcd91f85
product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
8adb41c0-b8dd-4e31-ae7b-959b4de938b1
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 23
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
5591e2a0-9d8e-42d2-99e0-62738897762d
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
e153e94c-35b3-46df-96b4-0c41ec542954
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 22
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
78f5dcad-be4e-4d57-82cd-adab32691a9e
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 24
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
51e3e0a3-8a75-43f8-8e8a-0c07345b88fd
product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803daLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 27
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
8b318d4f-0d42-46cd-a5a9-02337bb1d2f2
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 25
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
a921f4e5-6ba7-4978-b47e-d1b173ff493f
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 29
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
7bb77eff-a064-4475-a93c-5d5ba9313724
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 28
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
50f6cc82-cac7-426c-94f0-9e8e26cf61e0
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 26
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
2bf4f8c6-1c43-4a54-9fd6-011253744fc8
product-f87c7b9b64c86afcc0c48220bda1bc92543beefff7155621fe458a2627cfe653Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 33
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
29a3450e-ea73-4e17-b371-92f55ef6e1a9
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 32
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
ae2899e6-abef-4b61-ab8d-af060d571196
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 31
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
090fc11a-c085-4603-84e0-3abd6c571e2b
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 30
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
88acf2c5-fd3d-49be-8f32-13559a0c4a63
cpe:2.3:a:f5:big-ip_ddos_hybrid_defender:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 34
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
40239d12-142e-4d36-a89e-0f7ab91b665a
product-8f453bafc34e9c461b1290b73550569e7558e64398eede2e74d46d6cb72adae8Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 36
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
29a0b309-e321-4f87-9c36-cae4c213c14b
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 39
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
87ca1319-92d4-4c2f-b5d4-a2e86f538007
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 38
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
d4d4b28e-43b5-4132-a4ec-b20b9f85964a
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 37
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
f7c6025c-7283-4568-929b-cfa11423e179
cpe:2.3:a:f5:big-ip_domain_name_system:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 35
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
7689c97e-d5fb-427f-9fba-a41ca0ec7f06
product-e23ab53fe98a6d7dc5b97fdacee007e8bb696cfe3231c6ccc001c53853c3209cLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 44
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
7fe9ef68-055b-40b2-a676-c4c7faaf77b3
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 42
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
bbbad42c-06d5-437f-ab92-1dcc23c1a78b
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 40
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
9dc500f0-4d91-415e-b754-a89f730002f9
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 43
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
626e1218-868c-4328-99da-62785c6771df
cpe:2.3:a:f5:big-ip_fraud_protection_service:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 41
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
da2d429f-42c4-4872-977a-cdabd60f92e6
product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 49
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
bd28da4b-f671-41b8-b231-24d28682fe8f
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 45
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
b58942bf-915d-49f6-9e8a-2092d1ae572d
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 46
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
59be59f9-e6f3-4d48-89ac-6c4b5635a4e9
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 48
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
044f30a3-6b2e-4c38-8705-d291cd3cb287
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 47
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
3db5f9d2-c452-4469-9626-15fa11960a9c
product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dabLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 50
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
4fd31b8d-10ae-4e52-8235-6eb4a12d3965
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 54
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
47980a60-f9b6-47ee-ad74-4d6d03a71ad0
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 52
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
57388787-f9df-4930-acbc-f3d1daa53190
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 53
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
1d513aca-0d21-4ce0-88c1-dca812f62c05
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 51
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
0a9aa005-d0e3-43fc-9d21-9db8b5b9495d
product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 57
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
0af0d639-0210-47d0-8680-6e09f0111d5d
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 59
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
b0901863-b55a-4c97-b9ac-b537d242d2bf
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 58
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
86607f4a-555f-4842-afa8-34eb7484fa2e
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 56
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
94906b0a-46d2-41fc-bcfd-c66910274cd5
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 55
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
58a15dc4-30f5-407c-bce4-bc877c73480a
product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 60
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
d14a8876-b566-4a0c-886d-daec77bb3689
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 62
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
704df342-2cb5-4791-bf30-294d07b53653
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 64
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
85065c6e-71f2-42b8-a169-51174987b8af
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 61
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
45d3b1bc-568e-4bd8-8774-75203751c754
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 63
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
43cb3fea-4127-460b-846e-81b6c985deaa
product-c606d5370e1ae0f499fdbd5035f77ca02d8a84a54acabd597edb41f7a7690295Linked exactInspect raw assertions
cpe:2.3:a:f5:big-iq_centralized_management:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 65
- Logic
- OR
- Version bounds
- from including 6.0.0; through excluding 6.1.0
- Match ID
5262ca69-964f-4915-8ab6-0cdb655f3432
cpe:2.3:a:f5:big-iq_centralized_management:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 67
- Logic
- OR
- Version bounds
- from including 7.1.0; through excluding 7.1.0.3
- Match ID
f668dc7d-4b88-4ad8-b31c-e5afef49a983
cpe:2.3:a:f5:big-iq_centralized_management:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 66
- Logic
- OR
- Version bounds
- from including 7.0.0; through excluding 7.0.0.2
- Match ID
669308df-64ef-4a94-bf07-4e832bed05e2
product-cf4091ca4e2fda20d15e130d8a797ab0e11077ff758509d164c8e77b9177c404Linked exactInspect raw assertions
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 71
- Logic
- OR
- Version bounds
- from including 15.1.0; through excluding 15.1.2.1
- Match ID
628a35c2-d3d8-40a2-ba55-0910a38036e4
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 69
- Logic
- OR
- Version bounds
- from including 13.1.0; through excluding 13.1.3.6
- Match ID
6c5de2da-0daf-4ddf-9acb-daf301b97fb9
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 70
- Logic
- OR
- Version bounds
- from including 14.1.0; through excluding 14.1.4
- Match ID
c3fe49a0-46b4-49a1-92a4-1bea5bf48cdf
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 68
- Logic
- OR
- Version bounds
- from including 12.1.0; through excluding 12.1.5.3
- Match ID
34683a56-1665-47c7-a150-246b8a86c363
cpe:2.3:a:f5:ssl_orchestrator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 72
- Logic
- OR
- Version bounds
- from including 16.0.0; through excluding 16.0.1.1
- Match ID
14edd6bb-094c-409f-b702-ec87867eba17
Affected-product evidence
Accepted scope and product mapping
15 canonical links · 1 source-reported links
vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
05894b64-4081-4949-8310-bf166d70c6767fba9b75-77e9-4de5-b2f7-08ff2a848351a3fa76f8-eee3-4dfd-8e5c-863dad77fd24c2a5db22-aefe-4ad2-8197-241dd4e4c571f55546ad-be2d-4191-a89f-1ce059d8d438vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-3159127811fadcfbf55e58810b397c704a5ecb216e89a6fccc26cab6944674c7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0e3d1ef4-9ae8-4488-9d9d-07733cc2bf4a3777ca6e-ac80-4741-b881-d4132233ccd63a1986af-84e0-4434-b59a-b60f47ed9c3c891ef2a7-9da7-45da-a2ea-fb1aa8a850abab5e93c8-be76-4bfa-bdf5-707216e60d09vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
12c1d64c-5b5b-45ee-b535-1c2c1eaf47e242b4d825-0ad1-424b-9982-2f23757ae5a862c20882-955c-414e-bae0-d598b677f7b28c69ea34-c9f4-4e02-b2f9-c24346ae93c9b1f7200c-82d9-41c2-9331-8cd31a2c1f85vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dab
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
017955bf-39c2-41da-a35e-28f7bf2d4b7688154429-f538-44da-bc8d-4352c7308cb19069cd9f-19c3-433d-857a-c8387991fa89b05d068d-d770-4873-9e2e-066cdfca5409e821774a-9fa1-41b5-8e4b-9aec1ed802f3vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8f453bafc34e9c461b1290b73550569e7558e64398eede2e74d46d6cb72adae8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2bc0881b-9898-4d80-a82b-df7c4232fb156354ae9b-aa1a-496f-bb15-8daeadd920cbca445364-b334-468c-953b-128cb34d5e4ed2681018-ab85-418c-8e78-843c884d1c56ecd09c63-0b72-4348-9f9a-b4e1efeaf6cdvendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1dc1617b-ea77-401e-b4c6-61231502460022fea3d0-144f-4b7b-82ab-3d528d686edc8a3872a0-8cd0-4314-98d0-aa92b1fa6fb8e31785f6-ab39-4073-8b7f-78c18349a33ef391dacb-9fc6-4e07-bc82-77a6ddf5bed3vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803da
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
24d61913-3967-4b2a-afdf-960c289c967f40b4db47-cbce-4ab9-9ce5-6b68e103c31d61848b16-e3eb-4b85-9253-88fb74ecd248a6ef3a5d-ac4d-4387-ba98-d8037f215bb9df16a903-8d6d-43b1-bf07-e23297074cd4vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
33a3a72d-2855-4c41-9eb2-36b1c9385a48afce5aac-bd8a-4fb4-bfff-bd725dee0278c34139c2-23b4-4bf7-871f-6430a38a7377e29d0b39-9f99-4b53-89c2-3c67c839c957f92fb745-8803-4293-a9b6-451270ffbc9avendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-c606d5370e1ae0f499fdbd5035f77ca02d8a84a54acabd597edb41f7a7690295
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
127833ca-e60e-44cb-9454-66f6bb54dd779237586d-452c-4bd9-8738-446ae99bf73bf4b14054-6ccc-47fa-8133-436a4a76c0b2vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
46e2465b-675e-4bea-affd-d2e1eb1b65529b926402-80a2-4932-a895-752d2f1fd9f2b84a5142-ed89-4cde-a26c-e187f60ad18ee2604e8e-e0cc-4271-acc4-9ecf2c928054f349ced3-260d-4f1a-8113-b8fdb8f54596vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-cf4091ca4e2fda20d15e130d8a797ab0e11077ff758509d164c8e77b9177c404
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3ce50985-0c81-4fdb-8e46-ea899531816b454faccd-b1c8-4f64-b005-0b74b259d1815635d362-e621-46ba-a4e0-619e223881687f201e65-bde8-4f84-a4b8-a8037a027aa2d3ad3f65-5a8b-4613-9952-1ff3b9b1b549vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0aebdd8b-0793-46a6-9f99-0ce83f515e856efeef0d-e694-4ff3-92f0-c154a8975e249157ecc7-ba14-438b-8b53-efc5f7296ef7ca1d954b-e24a-4e7f-9fa6-11fc8d90b3f5fc00086d-d197-4ffc-b933-dbe5d2dcb292vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-e23ab53fe98a6d7dc5b97fdacee007e8bb696cfe3231c6ccc001c53853c3209c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
16ea99cc-bb26-41e4-a0e6-abfb2ac671bf3a0f2e51-ae5f-4cec-a811-b664e78d9932aaf24baa-7e46-4753-9325-c626ea0c946fb01b9c95-83a8-4b4b-825f-70dccd602cd7d9d67f7b-b125-4c39-81f3-ad2d1e251529vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-f87c7b9b64c86afcc0c48220bda1bc92543beefff7155621fe458a2627cfe653
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
368ffef4-0239-4281-be8e-eb6bb280335c47462fc2-7f14-4afc-81da-49d04498830e96d9f82e-591c-49d3-9089-f3854f780a3ea301cdf7-569c-470f-8afd-68d2c0a45c44d5509421-67a7-4155-8bf7-96441e4cb52cvendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2c0f91cf-4db9-4c8c-8c15-c2bee434c1ad3f91de34-5ce8-45f9-b55a-a8edc1b4e2146e6c2401-49c5-4e7a-8f06-7c3f7e40d1779c0ae7dc-9083-4084-9bc3-b6f7563a2f74b085cc61-2cef-4964-b14d-de2ec81e63b9Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
096b96f6-ceaa-48c8-9c3e-25e1641e11edAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.