# F5 Patches Multiple BIG-IP, NGINX Vulnerabilities

Published: 2026-09-03 · Severity: elevated · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/e826004b-3688-5279-876b-0d4a704e3022/f5-patches-multiple-big-ip-nginx-vulnerabilities

> CERT-FR advisory details multiple F5 vulnerabilities affecting BIG-IP, BIG-IQ, APM Clients and NGINX products enabling RCE, privilege escalation and DoS.

CERT-FR has issued an advisory covering multiple vulnerabilities discovered in F5 products, including BIG-IP, BIG-IP APM, APM Clients, BIG-IQ, NGINX Gateway Fabric, NGINX Ingress Controller, and NGINX JavaScript. The vulnerabilities span a wide range of impact types including remote code execution, privilege escalation, remote denial of service, data integrity and confidentiality breaches, security policy bypass, and server-side request forgery (SSRF). No active exploitation is mentioned in the advisory.

Affected versions include APM Clients prior to 7.2.6, BIG-IP APM 17.1.x prior to 17.1.3.1 and 17.5.x prior to 17.5.1.4, BIG-IP 17.1.x/17.5.x/21.0.x/21.1.x prior to various patched builds, BIG-IQ 8.4.x prior to 8.4.2.1, and several NGINX components (Gateway Fabric, Ingress Controller, JavaScript) prior to their respective fixed versions. Nine CVEs are referenced across nine separate F5 security bulletins published in early September 2026.

Organizations running F5 BIG-IP, BIG-IQ, or NGINX products should consult the referenced F5 security bulletins (K000162872, K000161728, K000162417, K000162521, K000162599-K000162603) to identify applicable patches and apply them according to their exposure. Given the range of impacts—particularly remote code execution and privilege escalation on widely deployed application delivery and ingress infrastructure—prompt patching is recommended, though the advisory does not indicate in-the-wild exploitation at time of publication.

## Mentioned in this report

- Vulnerabilities: CVE-2026-18329, CVE-2026-33278, CVE-2026-42959, CVE-2026-63020, CVE-2026-66362, CVE-2026-66842, CVE-2026-77180, CVE-2026-78222, CVE-2026-78689

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1111

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e826004b-3688-5279-876b-0d4a704e3022/f5-patches-multiple-big-ip-nginx-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
