
🚨 High - F5 BIG-IP / BIG-IQ Configuration Utility RCE (CVE-2026-41957) An authenticated deserialization vulnerability in the BIG-IP and BIG-IQ Configuration utility may allow attackers with management access to execute arbitrary system commands, create/delete files, or disable services on affected devices. F5 confirmed this is a control plane issue with no data plane exposure. 👉 Affected: • BIG-IP 17.5.0–17.5.1 • BIG-IP 17.1.0–17.1.3 • BIG-IP 16.1.0–16.1.6 • BIG-IQ 8.4.0 👉 Fixes: • BIG-IP 17.5.1.4 • BIG-IP 17.1.3.1 • BIG-IQ 8.4.1 ⚠️ No fix is available for BIG-IP 16.x - upgrade to a supported fixed branch. Mitigation: Restrict Configuration utility access to trusted networks/users only and block self-IP / management interface exposure where possible.
Post summary
F5 announced an authenticated deserialization RCE (CVE-2026-41957) affecting multiple BIG‑IP and BIG‑IQ versions, with specific patch releases and mitigation guidance provided.



