F5 Patches Critical Vulnerabilities in BIG-IP, NGINX, and Related Products

F5 Networks has released its Quarterly Security Notification, addressing multiple vulnerabilities that could expose enterprise infrastructures to severe risk.

While F5 internally classifies these flaws as “Medium” severity, the updated CVSS v4.0 scoring framework ranks the most critical issues at 8.2 (High), highlighting the potential impact on production environments running BIG-IP, NGINX, and related components.

High-Risk Vulnerabilities Identified

The advisory outlines three primary vulnerabilities affecting BIG-IP Advanced WAF, NGINX Plus, and BIG-IP Container Ingress Services (CIS).

Because these components handle critical application routing and load balancing operations, unpatched versions can become high-value entry points for attackers.

This vulnerability impacts BIG-IP Advanced Web Application Firewall (WAF) and Application Security Manager (ASM).

Scoring 8.2 (High), it could allow remote attackers to bypass security filters or disrupt web application protection mechanisms. The issue affects versions 17.1.0 through 17.1.2, with a patch available in 17.1.3.

A significant flaw has been identified in the NGINX ecosystem, including NGINX Open Source, NGINX Plus, and the NGINX Ingress Controller.

With a CVSS v4.0 score of 8.2, unpatched servers may allow privilege escalation or service manipulation.

NGINX Gateway Fabric and Instance Manager are also impacted, requiring individual patching according to deployment configurations.

Targeting Kubernetes and OpenShift users, the BIG-IP Container Ingress Services (CIS) vulnerability scores 6.9 (Medium) and affects versions 2.0.0 through 2.20.1. Upgrading to 2.20.2 resolves the issue and closes potential ingress control loopholes.

CVE IDComponentSeverity (CVSS v4.0)Affected Versions
CVE-2026-22548BIG-IP Adv. WAF / ASM8.2 (High)17.1.0 – 17.1.2
CVE-2026-1642NGINX Plus8.2 (High)R32 – R36 P1
CVE-2026-1642NGINX Open Source8.2 (High)1.3.0 – 1.29.4
CVE-2026-1642NGINX Ingress Controller8.2 (High)5.3.0 – 5.3.2
CVE-2026-22549BIG-IP Container Ingress6.9 (Medium)2.0.0 – 2.20.1
CVE-2026-20730BIG-IP Edge Client (Windows)2.0 (Low)7.2.5 – 7.2.6.1
CVE-2026-20732BIG-IP Config Utility2.3 (Low)17.1.0 – 17.1.3

F5 also disclosed a separate configuration exposure in BIG-IP SMTP modules (K000156643).

Although not a software flaw, misconfigured email relay settings could enable information leakage or unauthorized relay.

Administrators should apply the hardening measures introduced in versions 17.5.1.4 and 21.0.0.1.

  • Inventory Assets: Identify all in-scope BIG-IP and NGINX instances.
  • Verify Versions: Cross-check with the affected versions listed above.
  • Apply Patches: Implement urgently, especially for CVE-2026-22548 and CVE-2026-1642.
  • Harden Configurations: Review SMTP module settings to close configuration gaps.

Security teams should prioritize these updates to ensure the continued protection of application delivery pipelines and perimeter traffic management systems.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories