Multiple vulnerabilities in F5 products (July 16, 2026)
Multiple vulnerabilities have been discovered in F5 products. Some of them allow an attacker to cause remote arbitrary code execution, a remote denial of service, and a breach of data confidentiality.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to cause remote arbitrary code execution, a remote denial of service, and a breach of data confidentiality.
- Who is affected
- Users of F5 products are affected.
- Urgency
- Remediation is high urgency due to the severity of the vulnerabilities.
- Action
- Update F5 products to the latest versions as soon as possible.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0894/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-600650.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-600050.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all scored CVEs.
- Low exploitation riskCVE-2026-564340.45% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all scored CVEs.
- Low exploitation riskCVE-2026-528650.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
- Low exploitation riskCVE-2026-597620.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2026-557230.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all scored CVEs.
- Low exploitation riskCVE-2026-600620.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all scored CVEs.
- Moderate exploitation riskCVE-2026-463331.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 72% of all scored CVEs.
- Moderate exploitation riskCVE-2026-425333.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 88% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-60065 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60005 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56434 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-52865 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59762 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55723 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-60062 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46333 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42533 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] NGINX NGINX Plus: Multiple vulnerabilitiescert-bund
- unknownexploitedSiemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFPcisa
- unknown[Control Systems] Moxa security advisory (AV26-742)cccs
- medium[UPDATE] [medium] Linux Kernel: Vulnerability Allows Bypassing Security Measurescert-bund
- unknownVulnerability in Moxa products (July 24, 2026)cert-fr-avis
- unknownUSN-8563-2: nginx regressionubuntu
- highUSN-8569-1: Linux kernel (HWE) vulnerabilitiesubuntu
- unknownUSN-8563-1: nginx vulnerabilitiesubuntu
- medium[NEW] [medium] F5 BIG-IP and BIG-IP Next: Vulnerability allows Denial of Servicecert-bund
- highCVE-2026-60005: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. Whe…nvd
- lowCVE-2026-60065: When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter mod…nvd
- mediumCVE-2026-60062: The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read an…nvd
Recent advisories for F5 products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownF5 Products Multiple Vulnerabilitieshkcert · 2026-07-29
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31