F5 Patches Over 50 Vulnerabilities

https://www.securityweek.com/wp-content/uploads/2023/10/F5-Vulnerability.jpg

F5 on Wednesday announced fixes for over 19 high-severity and 32 medium-severity vulnerabilities impacting BIG-IP, BIG-IQ, and NGINX.

Based on the CVSS score, the most severe of the resolved issues is CVE-2026-42945 (CVSS v4.0 score of 9.2), a denial-of-service (DoS) condition in NGINX’s ngx_http_rewrite_module module.

The bug allows an unauthenticated attacker to send crafted HTTP requests that, combined with certain conditions beyond the attacker’s control, could trigger a heap buffer overflow and a restart. If Address Space Layout Randomization (ASLR) is disabled, the flaw can be exploited for code execution.

Next in line is CVE-2026-41225 (CVSS v4.0 score of 8.6), a weakness in iControl REST that could allow an authenticated attacker who has at least Manager permissions to create configuration objects, leading to command execution.

“This vulnerability may allow a highly privileged attacker with network access to the affected iControl REST endpoint through the BIG-IP management port or self IP...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE