Multiples vulnérabilités dans les produits F5 (16 juillet 2026)
Multiple vulnerabilities have been discovered in F5 products, including BIG-IP, WAF, and NGINX. These vulnerabilities could allow an attacker to achieve remote code execution, denial of service, and data confidentiality breaches. The CERT-FR is directing users to F5 security bulletins for specific patches and mitigations.
F5 has announced multiple security vulnerabilities affecting several of its products. These vulnerabilities could be exploited to compromise system integrity, steal sensitive data, and disrupt services. The CERT-FR is highlighting the need for immediate action to address these issues. The affected products include BIG-IP Next CNF versions 2.3.2, BIG-IP Next SPK versions at 2.0.3, BIG-IP versions prior to 21.1.0, F5 WAF versions prior to 5.13.3, NGINX Ingress Controller versions prior to 5.5.3, NGINX Open Source versions prior to 1.31.3, NGINX Plus versions prior to 37.0.3, and related components. The vulnerabilities are detailed in F5 security bulletins. Several CVEs have been identified, including CVE-2026-42533, CVE-2026-46333, CVE-2026-52865, CVE-2026-55723, CVE-2026-56434, CVE-2026-59762, CVE-2026-60005, and CVE-2026-60062. Users are strongly advised to consult the linked F5 security bulletins for detailed information and to apply the recommended patches immediately.