Junglewise Threat Intelligence

CVE-2026-41957: F5 BIG-IP and BIG-IQ RCE in Configuration utility

CVE-2026-41957 · Severity: high · CVSS 8.8 · Published 2026-05-13

Technologies: F5 Big-Iq Centralized Management, F5 BIG-IQ, F5 BIG-IP. Vendors: F5.

Executive brief

F5 BIG-IP and BIG-IQ devices, which are used for network traffic management and security, contain a vulnerability in their management interface. An attacker with low-level login credentials could take complete control of the device remotely. This could lead to the interception of network traffic, data theft, or a total disruption of network services.

Technical details

An authenticated remote code execution (RCE) vulnerability exists in the BIG-IP and BIG-IQ Configuration utility (management interface). The vulnerability is rooted in the deserialization of untrusted data (CWE-502). An attacker with network access to the management port and valid low-privileged credentials can exploit this flaw to execute arbitrary commands on the underlying operating system. The vulnerability affects multiple BIG-IP modules including APM, AFM, and ASM. F5 has released a vendor advisory (K000156761) detailing mitigations and affected versions.

Affected products

  • F5 BIG-IP 16.1.0 - 16.1.6, 17.5.0 - 17.5.1
  • F5 BIG-IQ Centralized Management 8.4.0

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability advisory

References

Related threats