F5 security advisory (AV26-878)
Canada's Cyber Centre relayed an F5 advisory (AV26-878) covering vulnerabilities in BIG-IP, BIG-IQ, NGINX components, and APM clients.
The Canadian Centre for Cyber Security published advisory AV26-878 noting F5 vulnerabilities affecting BIG-IP all modules prior to 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1, plus BIG-IQ prior to 8.4.2.1, NGINX Gateway Fabric, NGINX Ingress Controller, NGINX JavaScript 9.9, and APM clients. F5 issued an out-of-band security notification (K000162872) on September 2, 2026. Administrators are encouraged to review the linked advisory and apply updates as they become available.
- F5 BIG-IP all modules affected across the 17.1, 17.5, 21.0, and 21.1 branches
- BIG-IQ, NGINX Gateway Fabric, Ingress Controller, NGINX JavaScript, and APM clients also affected
- Based on F5 out-of-band notification K000162872 dated September 2, 2026
Full article99 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-878
Date: September 3, 2026
As of September 2, 2026, F5 is affected by vulnerabilities in the following products:
- BIG-IP (all modules)
- Prior to 17.1.3.4
- Prior to 17.5.1.8
- Prior to 21.0.0.3
- Prior to 21.1.0.1
- BIG-IQ
- Prior to 8.4.2.1
- NGINX Gateway Fabric
- Prior to 2.6.8
- NGINX Ingress Controller
- Prior to 2026-lts-r5
- Prior to 5.6.0
- NGINX JavaScript
- 9.9
- Prior to 1.0.1
- APM Clients
- Prior to 7.2.6
- BIG-IP APM
- Multiple versions
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/f5-security-advisory-av26-878