CVE-2026-41957Disclosure(f5 / big-ip_access_policy_manager)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch f5 big-ip_access_policy_manager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • big-ip_access_policy_manager
  • big-ip_advanced_firewall_manager
  • big-ip_advanced_web_application_firewall
  • big-ip_analytics

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-05-13); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
big-ip_access_policy_managerbig-ip_advanced_firewall_managerbig-ip_advanced_web_application_firewallbig-ip_analyticsbig-ip_application_acceleration_managerbig-ip_application_security_managerbig-ip_application_visibility_and_reportingbig-ip_automation_toolchainbig-ip_carrier-grade_natbig-ip_container_ingress_services

1 version affected across 22 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-13: 1Mentions · 2026-05-17: 1Mentions · 2026-05-18: 1Mentions · 2026-05-19: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-17: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 105-1305-1705-1805-19
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-131
Disclosure1
2026-05-171
Disclosure1
2026-05-181
Patch1
2026-05-191
Patch1
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High - F5 BIG-IP / BIG-IQ Configuration Utility RCE (CVE-2026-41957) An authenticated deserialization vulnerability in the BIG-IP and BIG-IQ Configuration utility may allow attackers with management access to execute arbitrary system commands, create/delete files, or disable services on affected devices. F5 confirmed this is a control plane issue with no data plane exposure. 👉 Affected: • BIG-IP 17.5.0–17.5.1 • BIG-IP 17.1.0–17.1.3 • BIG-IP 16.1.0–16.1.6 • BIG-IQ 8.4.0 👉 Fixes: • BIG-IP 17.5.1.4 • BIG-IP 17.1.3.1 • BIG-IQ 8.4.1 ⚠️ No fix is available for BIG-IP 16.x - upgrade to a supported fixed branch. Mitigation: Restrict Configuration utility access to trusted networks/users only and block self-IP / management interface exposure where possible.

    Post summary

    F5 announced an authenticated deserialization RCE (CVE-2026-41957) affecting multiple BIG‑IP and BIG‑IQ versions, with specific patch releases and mitigation guidance provided.

    00020135
    196 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: High severity vulnerability in #F5 #BIG-IP and #BIG-IQ CVE-2026-41957 CVSS: 8.8. An authenticated attacker can use the configuration utility to execute arbitrary system commands and fully compromise the system. #RCE More info: https://my.f5.com/manage/s/article/K000156761 #Patch #Patch #Patch

    Post summary

    The tweet announces a high‑severity CVE (2026‑41957) affecting F5 BIG‑IP and BIG‑IQ that allows authenticated remote code execution via the configuration utility, with patch information provided through a vendor advisory.

    00010347
    7.2K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-41957 | F5 BIG-IP/BIG-IQ prior 17.1.3.1/17.5.1.4 deserialization (K000156761 / WID-SEC-2026-1532) https://ift.tt/MqPHXNo A vulnerability marked as very critical has been reported in F5 BIG-IP and BIG-IQ. Affected is an unknown function. Performing a manipulation resul…

    Post summary

    A very critical deserialization vulnerability (CVE-2026-41957) affecting F5 BIG-IP and BIG-IQ devices prior to specific versions has been disclosed, with insufficient details about the affected function and no information about exploitation or fixes.

    0000044
    974 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting F5 BIG-IP and BIG-IQ (CVE-2026-41957) https://vuldb.com/vuln/363550

    Post summary

    A new vulnerability, CVE-2026-41957, affecting F5 BIG‑IP and BIG‑IQ has been announced with a link to a vulnerability database entry.

    0000067
    2.2K followersView on X
CPE platform detail22 entries

22 of 22 entries

PartVendorProductVersionTarget SWTarget HW
Appf5big-ip_access_policy_manager---
Appf5big-ip_advanced_firewall_manager---
Appf5big-ip_advanced_web_application_firewall---
Appf5big-ip_analytics---
Appf5big-ip_application_acceleration_manager---
Appf5big-ip_application_security_manager---
Appf5big-ip_application_visibility_and_reporting---
Appf5big-ip_automation_toolchain---
Appf5big-ip_carrier-grade_nat---
Appf5big-ip_container_ingress_services---
Appf5big-ip_ddos_hybrid_defender---
Appf5big-ip_domain_name_system---
Appf5big-ip_edge_gateway---
Appf5big-ip_fraud_protection_service---
Appf5big-ip_global_traffic_manager---
Appf5big-ip_link_controller---
Appf5big-ip_local_traffic_manager---
Appf5big-ip_policy_enforcement_manager---
Appf5big-ip_ssl_orchestrator---
Appf5big-ip_webaccelerator---
Appf5big-ip_websafe---
Appf5big-iq_centralized_management8.4.0--

Explore more