Skip to content
F5 Security Advisory Av26 878

F5 Security Advisory Av26 878

www.cyber.gc.ca September 6, 2026

As of September 2, 2026, F5 is affected by vulnerabilities in the following products:

BIG-IP (all modules) Prior to 17.1.3.4 Prior to 17.5.1.8 Prior to 21.0.0.3 Prior to 21.1.0.1

BIG-IQ Prior to 8.4.2.1

NGINX Gateway Fabric Prior to 2.6.8

NGINX Ingress Controller Prior to 2026-lts-r5 Prior to 5.6.0

NGINX JavaScript 9.9 Prior to 1.0.1

APM Clients Prior to 7.2.6

BIG-IP APM Multiple versions

The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.

K000162872: Out-of-band Security Notification (September 2, 2026)