F5 security advisory (AV26-878)
MediumCanadian Centre for Cyber Security · Canadian Centre for Cyber Security·
As of September 2, 2026, F5 is affected by vulnerabilities in the following products:
- BIG-IP (all modules)
- Prior to 17.1.3.4
- Prior to 17.5.1.8
- Prior to 21.0.0.3
- Prior to 21.1.0.1
- BIG-IQ
- Prior to 8.4.2.1
- NGINX Gateway Fabric
- Prior to 2.6.8
- NGINX Ingress Controller
- Prior to 2026-lts-r5
- Prior to 5.6.0
- NGINX JavaScript
- 9.9
- Prior to 1.0.1
- APM Clients
- Prior to 7.2.6
- BIG-IP APM
- Multiple versions
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Read at cyber.gc.ca ↗Official Source
Coverage
One outlet has carried this so far.
2026-09-03 14:05 UTC
Related stories
- Malware bypasses browser checks to force install Chrome, Edge extensions
BleepingComputer · 2026-09-16
- Google Pixel phones pwned in zero-click attacks
The Register · 2026-09-16
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16