ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security

F5 security advisory (AV26-878)

mediumAdvisoryimportance 28
AI summary · glm-5.3-flash

Canada's Cyber Centre relayed an F5 advisory (AV26-878) covering vulnerabilities in BIG-IP, BIG-IQ, NGINX components, and APM clients.

The Canadian Centre for Cyber Security published advisory AV26-878 noting F5 vulnerabilities affecting BIG-IP all modules prior to 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1, plus BIG-IQ prior to 8.4.2.1, NGINX Gateway Fabric, NGINX Ingress Controller, NGINX JavaScript 9.9, and APM clients. F5 issued an out-of-band security notification (K000162872) on September 2, 2026. Administrators are encouraged to review the linked advisory and apply updates as they become available.

  • F5 BIG-IP all modules affected across the 17.1, 17.5, 21.0, and 21.1 branches
  • BIG-IQ, NGINX Gateway Fabric, Ingress Controller, NGINX JavaScript, and APM clients also affected
  • Based on F5 out-of-band notification K000162872 dated September 2, 2026
Full article99 words · extracted from cyber.gc.ca · click to collapse

Serial Number: AV26-878
Date: September 3, 2026

As of September 2, 2026, F5 is affected by vulnerabilities in the following products:

  • BIG-IP (all modules)
    • Prior to 17.1.3.4
    • Prior to 17.5.1.8
    • Prior to 21.0.0.3
    • Prior to 21.1.0.1
  • BIG-IQ
    • Prior to 8.4.2.1
  • NGINX Gateway Fabric
    • Prior to 2.6.8
  • NGINX Ingress Controller
    • Prior to 2026-lts-r5
    • Prior to 5.6.0
  • NGINX JavaScript
    • 9.9
    • Prior to 1.0.1
  • APM Clients
    • Prior to 7.2.6
  • BIG-IP APM
    • Multiple versions

The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/f5-security-advisory-av26-878