As of September 2, 2026, F5 is affected by vulnerabilities in the following products:
BIG-IP (all modules) Prior to 17.1.3.4 Prior to 17.5.1.8 Prior to 21.0.0.3 Prior to 21.1.0.1
BIG-IQ Prior to 8.4.2.1
NGINX Gateway Fabric Prior to 2.6.8
NGINX Ingress Controller Prior to 2026-lts-r5 Prior to 5.6.0
NGINX JavaScript 9.9 Prior to 1.0.1
APM Clients Prior to 7.2.6
BIG-IP APM Multiple versions
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
K000162872: Out-of-band Security Notification (September 2, 2026)
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
