Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3874 articles · 153111 vulns · 37/41 feeds (7d)
← Back to list
EST
PRE-CVE
f5

F5 security advisory (AV26-461)

72% confidence

Description

F5 published security updates for multiple products including BIG-IP, BIG-IP APM, BIG-IP Advanced WAF/ASM, BIG-IP DDoS Hybrid Defender, BIG-IP Next CNF, BIG-IP Next SPK, BIG-IP Next for Kubernetes, BIG-IP PEM, BIG-IQ Centralized Management, F5 DoS for NGINX, F5 WAF for NGINX, NGINX App Protect DoS, NGINX App Protect WAF, NGINX Gateway Fabric, NGINX Ingress Controller, NGINX Instance Manager, NGINX Open Source, and NGINX Plus. Users and administrators are encouraged to review the updates and apply necessary patches.

Affected Products

VendorProductVersions
f5—BIG-IP (all modules) – multiple versions, BIG-IP APM – multiple versions, BIG-IP Advanced WAF/ASM – multiple versions, BIG-IP BIG-IP Advanced WAF/ASM and BIG-IP DDoS Hybrid Defender – multiple versions, BIG-IP Next CNF – versions 2.0.0 to 2.0.2, versions 1.1.0 to 1.4.0, BIG-IP Next CNF – versions 2.0.0 to 2.2.1, versions 1.1.0 to 1.4.1, BIG-IP Next SPK – versions 2.0.0 to 2.0.2, versions 1.7.0 to 1.7.15, BIG-IP Next SPK – versions 2.0.0 to 2.0.2, versions 1.7.0 to 1.7.16, BIG-IP Next SPK – versions 2.0.0 to 2.0.3, versions 1.7.0 to 1.9.2, BIG-IP Next for Kubernetes – version 2.0.0, BIG-IP Next for Kubernetes – versions 2.0.0 to 2.1.0, BIG-IP Next for Kubernetes – versions 2.0.0 to 2.1.1, BIG-IP PEM – multiple versions, BIG-IQ Centralized Management – version 8.4.0, F5 DoS for NGINX – version 4.8.0, F5 WAF for NGINX – versions 5.9.0 to 5.12.1, NGINX App Protect DoS – versions 4.3.0 to 4.7.0, NGINX App Protect WAF – versions 5.1.0 to 5.8.0, versions 4.9.0 to 4.16.0, NGINX Gateway Fabric – versions 2.0.0 to 2.5.1, versions 1.3.0 to 1.6.2, NGINX Ingress Controller – multiple versions, NGINX Instance Manager – versions 2.16.0 to 2.21.1, NGINX Open Source – versions 1.0.0 to 1.30.0, versions 0.6.27 to 0.9.7, NGINX Plus – versions R32 to R36

Related News (1 articles)

Tier B
CCCS Canada2h ago
F5 security advisory (AV26-461)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
PublishedMay 13, 2026
Last enriched2h ago
Tags
security updatemultiple productsf5 networks
Trending Score20
Source articles1
Independent1
Info Completeness4/14
Missing: cve_id, product, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-42945EXP
NGINX ngx_http_rewrite_module vulnerability
Trending: 75
MEDIUMCVE-2026-40701EXP
NGINX ngx_http_ssl_module vulnerability
Trending: 58
MEDIUMCVE-2026-42934EXP
NGINX ngx_http_charset_module vulnerability
Trending: 58
HIGHCVE-2026-40629EXP
BIG-IP SSL/TLS vulnerability
Trending: 56
HIGHCVE-2026-40618EXP
BIG-IP SSL/TLS vulnerability
Trending: 56

Pin to Dashboard

Verification

State: reported
Confidence: 72%

Vulnerability Timeline

CVE Published
May 13, 2026
Discovered by ZDM
May 13, 2026