
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-41957 is an authenticated remote code execution (RCE) vulnerability affecting the F5 BIG-IP and BIG-IQ Configuration utility, exploitable through undisclosed vectors. It was published on May 13, 2026, and assigned by F5 (assigner: f5). Affected products include BIG-IP versions 16.1.0 and later (up to but not including fixed releases), BIG-IP 17.1.0 < 17.1.3.1, BIG-IP 17.5.0 < 17.5.1.4, and BIG-IQ 8.4.0 < 8.4.1; software versions that have reached End of Technical Support (EoTS) are not evaluated. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, F5 Advisory).
The vulnerability is classified under CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection), indicating that the Configuration utility improperly deserializes attacker-controlled data, enabling arbitrary code execution (GitHub Advisory). The specific attack vectors and affected endpoints are undisclosed by F5, which is consistent with the vendor's practice of withholding technical details to limit exploitation risk. Exploitation requires network access and low-level authenticated privileges (PR:L), with no user interaction or special attack conditions needed, making it accessible to any authenticated user on the system (GitHub Advisory).
Successful exploitation allows an authenticated low-privilege user to execute arbitrary code remotely on the BIG-IP or BIG-IQ system via the Configuration utility, resulting in full system compromise. This includes unauthorized access to sensitive configuration data and credentials (high confidentiality impact), modification of system configuration and traffic policies (high integrity impact), and potential disruption of load balancing and application delivery services (high availability impact). Given BIG-IP's role as a critical network infrastructure component, compromise could facilitate lateral movement into protected network segments or interception of application traffic (GitHub Advisory, F5 Advisory).
As of the time of reporting, there is no public proof-of-concept (PoC) exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.68% (72nd percentile), indicating a moderate relative probability of exploitation within 30 days compared to other CVEs. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (GitHub Advisory).
F5 has released patches addressing this vulnerability: BIG-IP 17.1.3.1, BIG-IP 17.5.1.4, and BIG-IQ 8.4.1 are the fixed versions; administrators should consult the F5 advisory for the full list of patched releases (F5 Advisory). As an immediate workaround, restrict network access to the BIG-IP/BIG-IQ Configuration utility (typically port 443/8443) to only trusted, authorized IP ranges using management network ACLs or firewall rules. Additionally, apply the principle of least privilege to accounts with access to the Configuration utility and monitor for anomalous authenticated activity. Software versions at End of Technical Support (EoTS) will not receive patches and should be upgraded (GitHub Advisory).
F5 disclosed this vulnerability as part of a quarterly security update in May 2026 that addressed over 50 vulnerabilities across BIG-IP, BIG-IQ, and NGINX products (SecurityWeek). Coverage was picked up by multiple security news outlets and national CERTs, including Thailand's ThaiCERT and Singapore's CSA, which issued advisories urging prompt patching (CSA Advisory). Heise and other technical media highlighted the breadth of the F5 quarterly patch release, noting the RCE vulnerabilities as the most critical items requiring immediate attention (Heise).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."