Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5329 articles · 221079 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-66842PATCHED
f5 · big-ip

BIG-IP and BIG-IQ Configuration utility vulnerability

Description

BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5big-ip21.1.0, 21.0.0, 17.5.0, 17.1.0, 8.4.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
f5big-ipcert_advisory90%

References

  • https://my.f5.com/manage/s/article/K000162521(vendor-advisory)

Related News (3 articles)

Tier B
BSI Advisories19d ago
[NEU] [hoch] F5 BIG-IP: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR19d ago
Multiples vulnérabilités dans les produits F5 (03 septembre 2026)
→ No new info (linked only)
Tier C
VulDB20d ago
CVE-2026-66842 | F5 BIG-IP/BIG-IQ TMUI privileges management
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
21.1.0.121.0.0.317.5.1.817.1.3.48.4.2.1
CWECWE-918
PublishedSep 2, 2026
Trending Score6
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-94127EXPKEV
BIG-IP APM OAuth vulnerability
Trending: 141
MEDIUMCVE-2026-90439
NGINX ngx_http_v3_module vulnerability
Trending: 26
HIGHCVE-2026-78222
NGINX ngx_http_js_module vulnerability
Trending: 6
HIGHCVE-2026-18329
NGINX ngx_http_js_module vulnerability
Trending: 6
HIGHCVE-2026-78689
NGINX ngx_http_js_module vulnerablility
Trending: 5

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 2, 2026
Discovered by ZDM
Sep 2, 2026
Patch Available
Sep 3, 2026