{"id":10443,"date":"2026-02-06T10:06:01","date_gmt":"2026-02-06T10:06:01","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/06\/f5-patches-critical-vulnerabilities-in-big-ip-nginx-and-related-products\/"},"modified":"2026-02-06T10:06:01","modified_gmt":"2026-02-06T10:06:01","slug":"f5-patches-critical-vulnerabilities-in-big-ip-nginx-and-related-products","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/06\/f5-patches-critical-vulnerabilities-in-big-ip-nginx-and-related-products\/","title":{"rendered":"F5 Patches Critical Vulnerabilities in BIG-IP, NGINX, and Related Products"},"content":{"rendered":"<p>    F5 Patches Critical Vulnerabilities in BIG-IP, NGINX, and Related Products<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>F5 released its February 2026 Quarterly Security Notification on February 4, announcing several medium and low-severity CVEs, plus a security exposure affecting BIG-IP, NGINX, and container services.<\/p>\n<p>These issues primarily stem from denial-of-service (DoS) risks and configuration weaknesses, potentially disrupting high-traffic environments like <a href=\"https:\/\/cybersecuritynews.com\/best-web-application-firewall-waf\/\" type=\"post\" id=\"11214\" target=\"_blank\" rel=\"noreferrer noopener\">web application firewalls<\/a> (WAF) and Kubernetes ingress.<\/p>\n<p>While no active exploits are reported, prompt patching is urged for internet-facing deployments to mitigate DoS chains or unauthorized access.<\/p>\n<p>F5 provides CVSS v3.1 and v4.0 scores for first-party issues, emphasizing attack vector, privileges, and impact. A live briefing video is available via DevCentral. Details link to F5\u2019s knowledge base.<\/p>\n<p>These three flaws pose moderate DoS threats, with CVSS scores up to 8.2 (v4.0). Attackers could overwhelm services remotely.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Article (CVE)<\/th>\n<th>CVSS v3.1 \/ v4.0<\/th>\n<th>Affected Products<\/th>\n<th>Affected Versions<\/th>\n<th>Fixes Introduced In<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000158072\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">K000158072: BIG-IP Advanced WAF\/ASM (CVE-2026-22548)<\/a><\/td>\n<td>5.9 \/ 8.2<\/td>\n<td>BIG-IP Advanced WAF\/ASM<\/td>\n<td>17.1.0 \u2013 17.1.2<\/td>\n<td>17.1.3<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000159824\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">K000159824: NGINX (CVE-2026-1642)<\/a><\/td>\n<td>5.9 \/ 8.2<\/td>\n<td>NGINX Plus (R32-R36 P1), Open Source (1.3.0-1.29.4), Ingress Controller (5.3.0-5.3.2; 4.0.0-4.0.1; 3.4.0-3.7.1), Gateway Fabric (2.0.0-2.4.0; 1.2.0-1.6.2), Instance Manager (2.15.1-2.21.0)<\/td>\n<td>R36 P2, R35 P1, R32 P4; 1.29.5, 1.28.2; None; None; None<\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000157960\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">K000157960: BIG-IP CIS (CVE-2026-22549)<\/a><\/td>\n<td>4.9 \/ 6.9<\/td>\n<td>BIG-IP Container Ingress Services (Kubernetes\/OpenShift)<\/td>\n<td>2.0.0-2.20.1; 1.0.0-1.14.0<\/td>\n<td>2.20.2; 2.20.1 (Helm 0.0.363)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><strong>Impact Assessment<\/strong>: CVE-2026-1642 affects the broadest NGINX ecosystem, enabling network-adjacent DoS via crafted requests. WAF\/ASM and CIS flaws target F5\u2019s containerized services, risking outages in hybrid clouds.<\/p>\n<p>Lower-risk issues focus on local or adjacent attacks.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Article (CVE)<\/th>\n<th>CVSS v3.1 \/ v4.0<\/th>\n<th>Affected Products<\/th>\n<th>Affected Versions<\/th>\n<th>Fixes Introduced In<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000158931\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">K000158931: BIG-IP Edge Client (CVE-2026-20730)<\/a><\/td>\n<td>3.3 \/ 2.0<\/td>\n<td>BIG-IP APM (21.0.0; 17.5.0-17.5.1; etc.); APM Clients<\/td>\n<td>17.1.3.13; 7.2.6.2<\/td>\n<td>17.1.3.1<sup>3<\/sup>, 7.2.6.2<\/td>\n<\/tr>\n<tr>\n<td><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000156644\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">K000156644: BIG-IP Config Utility (CVE-2026-20732)<\/a><\/td>\n<td>3.1 \/ 2.3<\/td>\n<td>BIG-IP (all modules)<\/td>\n<td>17.5.1.4; 17.1.3.1<\/td>\n<td>17.5.1.4<br \/>17.1.3.1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><strong>Notes<\/strong>: Edge Client requires Component Update enabled post-upgrade. Config utility flaw allows local privilege escalation.<\/p>\n<h2 class=\"wp-block-heading\" id=\"security-exposures\">Security Exposures<\/h2>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Article<\/th>\n<th>Affected Products<\/th>\n<th>Affected Versions<\/th>\n<th>Fixes Introduced In<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000156643\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">K000156643: BIG-IP SMTP Config<\/a><\/td>\n<td>BIG-IP (all modules)<\/td>\n<td>21.0.0; 17.5.0-17.5.1; etc.<\/td>\n<td>21.0.0.1; 17.5.1.4; 17.1.3.1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>This exposure risks SMTP misconfigurations leading to relay abuse.<\/p>\n<p>Prioritize medium CVEs in NGINX-heavy setups. Scan for affected versions (pre-EoTS only), apply fixes via iHealth or Helm for CIS. Test in staging to avoid disruptions. Monitor the Medium, Low, and Exposures pages. F5\u2019s CVSS v4.0 shift aids precise risk scoring, see <a href=\"https:\/\/my.f5.com\/manage\/s\/article\/K000140363\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">K000140363<\/a>.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/f5-patches-critical-vulnerabilities\/\">F5 Patches Critical Vulnerabilities in BIG-IP, NGINX, and Related Products<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/f5-patches-critical-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>F5 Patches Critical Vulnerabilities in BIG-IP, NGINX, and Related Products F5 released its February 2026 Quarterly Security Notification on February 4, announcing several medium and low-severity CVEs, plus a security exposure affecting BIG-IP, NGINX, and container services. These issues primarily stem from denial-of-service (DoS) risks and configuration weaknesses, potentially disrupting high-traffic environments like web application [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-10443","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10443"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10443"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10443\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10443"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10443"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10443"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}