VORANT. Threat Intelligence Sign in Get the full feed

F5 patches multiple BIG-IP, NGINX flaws

medium vulnerability technologyinfrastructure

ANSSI warns of multiple vulnerabilities in F5 BIG-IP, BIG-IP Next, F5 WAF and NGINX products enabling remote code execution, denial of service and data disclosure.

France's CERT-FR issued an advisory covering multiple vulnerabilities affecting a range of F5 products, including BIG-IP Next CNF, BIG-IP Next SPK, BIG-IP, F5 WAF, and multiple NGINX variants (Ingress Controller, Open Source, and Plus). The flaws collectively allow remote code execution, remote denial of service, data confidentiality breaches, data integrity compromise, and security policy bypass.

Nine CVEs are referenced in the advisory (CVE-2026-42533, CVE-2026-46333, CVE-2026-52865, CVE-2026-55723, CVE-2026-56434, CVE-2026-59762, CVE-2026-60005, CVE-2026-60062, CVE-2026-60065), tied to eight separate F5 security bulletins published on 15 July 2026. No exploitation in the wild is mentioned in the advisory; it is a standard vendor patch notification. Organizations running affected BIG-IP and NGINX deployments should apply F5's published fixes referenced in the linked bulletins.

Mentioned in this report

Vulnerabilities CVE-2026-42533CVE-2026-46333weaponizedCVE-2026-52865CVE-2026-55723CVE-2026-56434CVE-2026-59762CVE-2026-60005CVE-2026-60062CVE-2026-60065

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0894

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free