F5 BIG-IP Edge Client and Browser VPN Clients for Windows Sensitive Information Disclosure Vulnerability

Vulnerability

A vulnerability in F5 BIG-IP Edge Client and browser VPN clients on Windows may allow attackers to access sensitive information. This issue affects BIG-IP APM clients version 7.2.5 through 7.2.6.1, as well as BIG-IP APM versions 16.1.0 to 16.1.6, 17.1.0 to 17.1.3, and 21.0.0.

Impact

Exploitation of this vulnerability could enable an attacker with local access to list processes and retrieve session ID information, URLs, and other data being transmitted to executed binaries.

Remediation

Users can update to BIG-IP APM client versions 7.2.6.2 or to a vulnerable BIG-IP APM version 17.1.3.1. For more information about BIG-IP Edge Client versions, refer to the F5 knowledge articles K52547540 and K13757.

Added: Feb 4, 2026, 3:20 PM
Updated: Feb 4, 2026, 4:54 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
2.5
exploitability
2.4
remediation
7.7
relevance
2.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.