F5 issued an out-of-band security notification, K000162872, addressing vulnerabilities affecting BIG-IP, BIG-IQ, NGINX Gateway Fabric, NGINX Ingress Controller, NGINX JavaScript, APM Clients, and BIG-IP APM. The Canadian Centre for Cyber Security and Guyana National CIRT published advisories urging organizations to review the notification and deploy the applicable vendor remediations.
Affected BIG-IP installations include systems running releases earlier than 17.1.3.4, 17.5.1.8, 21.0.0.3, or 21.1.0.1; affected NGINX Ingress Controller versions are earlier than 2026-lts-r5 and 5.6.0. Administrators should identify exposed F5 deployments, validate installed modules and versions, and prioritize upgrades to the specified fixed releases when available.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-878 describing the affected F5 products and advising users and administrators to review F5 notification K000162872 and apply necessary updates.
F5 published security advisory SOL000162417 for BIG-IP Access Policy Manager, with a corresponding patch released on the same date. Tenable's local-check plugin reported no known exploits but did not provide a CVE identifier or fixed-version details.
CVE-2026-78689 was published as an unpatched vulnerability affecting Debian 12.0, 13.0, and 14.0 installations of libnginx-mod-js. Tenable reported network reachability, no required privileges or user interaction, high confidentiality, integrity, and availability impacts, and no known exploits at publication.
CVE-2026-18329 was published affecting Debian Linux 12.0, 13.0, and 14.0, including the libnginx-mod-js package. Tenable classified it as unpatched, network-reachable, and low complexity with no known exploits available.
F5 published CVE-2026-66842, a CVSS 8.8 network-accessible vulnerability affecting BIG-IP and multiple modules, including APM, AFM, ASM, DNS, LTM, and SSL Orchestrator. Patch information was published the same day; the referenced Nessus plugin reported no known public exploits at the time.
F5 issued out-of-band security notification K000162872 addressing vulnerabilities affecting BIG-IP, BIG-IQ, NGINX Gateway Fabric, NGINX Ingress Controller, NGINX JavaScript, APM Clients, and BIG-IP APM. The notification identified affected releases and directed customers to apply applicable fixed updates.
CVE-2026-13204 was published affecting F5 BIG-IP DNS and Global Traffic Manager components, including BIG-IP hardware. The remotely reachable, low-complexity vulnerability has a CVSS v3.0 score of 7.5 and high availability impact; no known exploits were available.
SophosLabs analyzed a Linux second-stage implant, also called PoisonedRefresh by ESET and detected as Linux/Agnt-IC, associated with F5 BIG-IP APM systems compromised through CVE-2025-53521. The implant injects an in-memory PHP web shell into APM webtop files and establishes an authenticated UNIX-domain-socket backdoor at /run/bigtlog.pipe; Sophos found insufficient evidence to attribute the activity to a specific threat actor.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
sophos.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcetenable.com
Open sourcecirt.gy
Open sourcetenable.com
Open sourcetenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.