F5 Networks has released its Quarterly Security Notification, addressing multiple vulnerabilities that could expose enterprise infrastructures to severe risk.
While F5 internally classifies these flaws as “Medium” severity, the updated CVSS v4.0 scoring framework ranks the most critical issues at 8.2 (High), highlighting the potential impact on production environments running BIG-IP, NGINX, and related components.
High-Risk Vulnerabilities Identified
The advisory outlines three primary vulnerabilities affecting BIG-IP Advanced WAF, NGINX Plus, and BIG-IP Container Ingress Services (CIS).
Because these components handle critical application routing and load balancing operations, unpatched versions can become high-value entry points for attackers.
This vulnerability impacts BIG-IP Advanced Web Application Firewall (WAF) and Application Security Manager (ASM).
Scoring 8.2 (High), it could allow remote attackers to bypass security filters or disrupt web application protection mechanisms. The issue affects versions 17.1.0 through 17.1.2, with a patch available in 17.1.3.
A significant flaw has been identified in the NGINX ecosystem, including NGINX Open Source, NGINX Plus, and the NGINX Ingress Controller.
With a CVSS v4.0 score of 8.2, unpatched servers may allow privilege escalation or service manipulation.
NGINX Gateway Fabric and Instance Manager are also impacted, requiring individual patching according to deployment configurations.
Targeting Kubernetes and OpenShift users, the BIG-IP Container Ingress Services (CIS) vulnerability scores 6.9 (Medium) and affects versions 2.0.0 through 2.20.1. Upgrading to 2.20.2 resolves the issue and closes potential ingress control loopholes.
| CVE ID | Component | Severity (CVSS v4.0) | Affected Versions |
|---|---|---|---|
| CVE-2026-22548 | BIG-IP Adv. WAF / ASM | 8.2 (High) | 17.1.0 – 17.1.2 |
| CVE-2026-1642 | NGINX Plus | 8.2 (High) | R32 – R36 P1 |
| CVE-2026-1642 | NGINX Open Source | 8.2 (High) | 1.3.0 – 1.29.4 |
| CVE-2026-1642 | NGINX Ingress Controller | 8.2 (High) | 5.3.0 – 5.3.2 |
| CVE-2026-22549 | BIG-IP Container Ingress | 6.9 (Medium) | 2.0.0 – 2.20.1 |
| CVE-2026-20730 | BIG-IP Edge Client (Windows) | 2.0 (Low) | 7.2.5 – 7.2.6.1 |
| CVE-2026-20732 | BIG-IP Config Utility | 2.3 (Low) | 17.1.0 – 17.1.3 |
F5 also disclosed a separate configuration exposure in BIG-IP SMTP modules (K000156643).
Although not a software flaw, misconfigured email relay settings could enable information leakage or unauthorized relay.
Administrators should apply the hardening measures introduced in versions 17.5.1.4 and 21.0.0.1.
- Inventory Assets: Identify all in-scope BIG-IP and NGINX instances.
- Verify Versions: Cross-check with the affected versions listed above.
- Apply Patches: Implement urgently, especially for CVE-2026-22548 and CVE-2026-1642.
- Harden Configurations: Review SMTP module settings to close configuration gaps.
Security teams should prioritize these updates to ensure the continued protection of application delivery pipelines and perimeter traffic management systems.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.