F5 Patches DoS Flaws in BIG-IP and NGINX
F5 patches DoS flaws across its BIG-IP, NGINX, and container platforms in its latest February 2026 security notification. The company addressed several medium to low-severity vulnerabilities, mainly tied to denial-of-service risks and configuration weaknesses. These flaws threaten services such as web application firewalls and Kubernetes ingress controllers, especially in high-traffic environments.
While F5 reported no active exploitation, it urges customers to update internet-facing systems quickly. CVE-2026-1642, affecting a wide range of NGINX products, presents the most extensive threat, with a CVSS v4.0 score of 8.2. Additional issues impact BIG-IP Advanced WAF/ASM and Container Ingress Services, possibly leading to service outages.
Other vulnerabilities, including those in BIG-IP Edge Client and the configuration utility, allow local privilege escalation or abuse of SMTP settings. F5 recommends scanning deployments and testing fixes in staging.
For further technical breakdowns and access to patch documentation, read the full update here:
F5 Patches Critical Vulnerabilities in BIG-IP, NGINX, and Related Products
