Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS
Vulnerability in F5 Products (CVE-2026-42015) (TL-2026-2660), also tracked as A26-09-38, is a medium-severity software vulnerability, first published 2026-09-24. It has no confirmed attribution, affects F5, Inc. BIG-IP Next CNF, references 1 CVE (CVE-2026-42015), maps to 9 MITRE ATT&CK techniques (T1190, T1195, T1499.004), and is covered by 9 detection rules and 10 indicators of compromise.
Key facts for TL-2026-2660
- Threat ID
- TL-2026-2660
- Also known as
- A26-09-38
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-24
- Last reviewed
- 2026-09-24
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, technology, telecoms, critical-infrastructure
- Target regions
- Asia-Pacific, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 10
GovCERT.HK/HKCERT issued Security Alert A26-09-38 on 2026-09-24 for CVE-2026-42015, which F5 Advisory K000163397 states affects BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS, F5OS-A, and F5OS-C, with impact described as denial of service and tampering. No CVSS score, active-exploitation confirmation, or public PoC is stated, and F5 says updates/mitigations are already available. Independent verification found the CVE ID as registered in NVD and Tenable actually maps to an unrelated GnuTLS PKCS#12 flaw affecting Red Hat products — a discrepancy defenders should resolve with F5/HKCERT before relying on the ID alone.
How Vulnerability in F5 Products (CVE-2026-42015) works
GovCERT.HK (operating on behalf of HKCERT) published Security Alert A26-09-38 on 24 September 2026, forwarding an F5 vendor advisory (K000163397) for CVE-2026-42015. Per the alert, the vulnerability affects BIG-IP Next CNF versions 1.4.0-1.4.2, BIG-IP Next for Kubernetes versions 2.2.0-2.2.2 and 2.3.0, F5OS version 2.0.0, F5OS-A versions 1.5.1-1.5.4 and 1.8.0-1.8.4, and F5OS-C versions 1.6.0-1.6.4 and 1.8.0-1.8.2. The stated impact of successful exploitation is denial of service and tampering on an affected system. Neither the alert nor any source located during this research states a CVSS score, an attack vector (network vs. local, authentication requirement), a root-cause/CWE classification, evidence of a public proof-of-concept, or evidence of active in-the-wild exploitation. F5's advisory states software updates and mitigations for the affected versions were already available at the time of disclosure; F5's own knowledge-base article (my.f5.com, article K000163397) could not be retrieved directly in this research pass because the portal renders its advisory body client-side and returned no substantive content to automated fetches — the technical detail on affected-fix versions and any workaround therefore rests on the HKCERT re-publication rather than the primary F5 text.
IMPORTANT SOURCING CAVEAT: cross-checking CVE-2026-42015 against NVD's REST API and against Tenable's CVE database returned a completely different, unrelated vulnerability: an off-by-one bounds-check error in GnuTLS's PKCS#12 bag-element handling (CWE-193), which allows memory corruption when appending to a bag already containing 32 elements, scored CVSS v3.1 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) and affecting Red Hat Enterprise Linux 7-10 and related products (GnuTLS Security Advisory GNUTLS-SA-2026-04-29-11, Red Hat Bugzilla #2467678, RHSA-2026 series advisories). This record has no relationship to F5, BIG-IP, F5OS, or Kubernetes. Because CVE identifiers are meant to be uniquely assigned by a single CNA, this is very unlikely to be a legitimate shared ID — it is far more consistent with a citation/typo error either in F5's own advisory K000163397 or in HKCERT's transcription of it (the correct F5-side CVE for this product/version/impact combination could not be independently located under a different number during this research pass — the affected-product fingerprint does not match any other September 2026 F5 CVE found, including the CVE-2026-33278 / CVE-2026-34986 / CVE-2026-42959 batch HKCERT published on 2026-09-02 for an overlapping BIG-IP Next CNF/Kubernetes/SPK/DNS product set). CVE-2026-42015 is also absent from the CISA Known Exploited Vulnerabilities catalog as of 2026-09-25, consistent with either identifier. Analysts should treat the product/version/impact facts from the HKCERT alert as reliable (they are corroborated internally and match the hunt-phase source), but should NOT pull CVSS, CWE, or technical root-cause detail for CVE-2026-42015 from NVD/Tenable/vulnerability-database tooling, since that data belongs to the unrelated GnuTLS issue — verify the true identifier directly with F5 support before scoring or ticketing this item by CVE number alone.
This disclosure lands in an elevated-risk period for F5 products. In August 2025 F5 identified a long-term, previously undetected compromise of its own corporate network by a nation-state actor, publicly disclosed 15-16 October 2025; the actor exfiltrated BIG-IP source code, information on undisclosed vulnerabilities, and implementation/configuration data for a subset of customers from an internal knowledge-management platform (Unit 42; NCSC UK). CISA responded with Emergency Directive ED 26-01, ordering federal agencies to inventory all BIG-IP (F5OS), BIG-IP (TMOS), BIG-IP Virtual Edition, BIG-IP Next, BIG-IQ, and BNK/CNF instances, check whether management interfaces are internet-exposed, and patch critical systems by 22 October 2025 and remaining devices by 31 October 2025 — the same product family named in this alert. F5 subsequently accelerated its disclosure cadence (45 vulnerabilities in the quarter following the breach vs. 6 the prior quarter), and the pattern has continued through 2026: an out-of-band notification on 2 September 2026 covered further BIG-IP Next CNF/Kubernetes/SPK/DNS issues (CVE-2026-33278, CVE-2026-34986, CVE-2026-42959, DoS and RCE impact), and a separate, unrelated critical BIG-IP APM OAuth-server heap-overflow RCE (CVE-2026-94127, CVSS 9.8) was confirmed under active exploitation and added to the CISA KEV catalog on 22 September 2026 — two days before this alert. Because the threat actor behind the 2025 breach retains stolen BIG-IP source code and undisclosed-vulnerability knowledge that CISA assessed can be used to "develop targeted exploits," any newly disclosed F5 vulnerability in this window carries elevated scrutiny even absent independent confirmation of active exploitation for this specific CVE.
Architecturally, BIG-IP Next CNF and BIG-IP Next for Kubernetes are F5's containerized, cloud-native network functions built to run on Kubernetes/OpenShift for telco, 5G, and cloud-edge traffic-processing use cases, while F5OS (and its F5OS-A/F5OS-C variants) is the base operating system F5 ships on its rSeries/iSeries hardware appliances and that underlies BIG-IP Next deployments. A denial-of-service-and-tampering flaw in this layer therefore has the potential to affect inline, traffic-processing network functions and/or the host OS layer beneath a BIG-IP Next fleet rather than a peripheral management tool, which is consistent with the MEDIUM severity assessment in the absence of a stated CVSS score, RCE, or data-disclosure impact.
Remediation: apply F5's published fix for the affected BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS, F5OS-A, and F5OS-C versions per Advisory K000163397 as soon as operationally feasible; confirm whether management interfaces on these devices are internet-exposed and remediate per the same guidance CISA issued in ED 26-01 for this product family; and independently verify the correct CVE identifier with F5 support given the CVE-2026-42015/GnuTLS collision documented above before using the ID in scanning, ticketing, or KEV/NVD-driven prioritization tooling.
MITRE ATT&CK techniques used in TL-2026-2660
Initial Access
T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise
Impact
T1499.004 Application or System Exploitation; T1565 Data Manipulation
Resource Development
T1587.004 Exploits; T1588.006 Vulnerabilities
Reconnaissance
T1592.002 Software; T1595.002 Vulnerability Scanning
Defense Impairment
Affected products and versions in Vulnerability in F5 Products (CVE-2026-42015)
- F5, Inc. — BIG-IP Next CNF
Vulnerable versions: 1.4.0-1.4.2
Fixed in: See F5 Advisory K000163397 for the specific fixed release - F5, Inc. — BIG-IP Next for Kubernetes
Vulnerable versions: 2.2.0-2.2.2; 2.3.0
Fixed in: See F5 Advisory K000163397 for the specific fixed release - F5, Inc. — F5OS
Vulnerable versions: 2.0.0
Fixed in: See F5 Advisory K000163397 for the specific fixed release - F5, Inc. — F5OS-A
Vulnerable versions: 1.5.1-1.5.4; 1.8.0-1.8.4
Fixed in: See F5 Advisory K000163397 for the specific fixed release - F5, Inc. — F5OS-C
Vulnerable versions: 1.6.0-1.6.4; 1.8.0-1.8.2
Fixed in: See F5 Advisory K000163397 for the specific fixed release
Remediation for Vulnerability in F5 Products (CVE-2026-42015)
Patches
- F5 Advisory K000163397 (software updates/mitigations for the affected BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS, F5OS-A, F5OS-C versions were stated as available at disclosure)
Immediate actions
- Apply the F5 fix for the affected BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS, F5OS-A, and F5OS-C versions referenced in Advisory K000163397
- Inventory all in-scope F5OS/BIG-IP Next/BNK-CNF instances and confirm whether their management interfaces are internet-accessible, per the exposure check CISA directed for this exact product family in ED 26-01
- Independently confirm the correct CVE identifier for this fix with F5 support before using CVE-2026-42015 in scanner/ticketing/KEV-driven prioritization workflows, given the documented ID collision with an unrelated GnuTLS CVE
Workarounds
- No vendor-published interim workaround beyond patching was found in the sources reviewed; consult F5 Advisory K000163397 directly for any interim mitigation guidance not captured by automated retrieval of the my.f5.com portal
Longer-term hardening
- Track F5's accelerated post-breach disclosure cadence and CISA KEV additions for the BIG-IP/F5OS/BIG-IP Next product family given the 2025 nation-state theft of BIG-IP source code and undisclosed-vulnerability data
- Enable F5 event streaming to SIEM and apply F5's fleet hardening guidance across BIG-IP Next Central Manager-managed deployments
- Restrict and monitor administrative/management-plane access to F5OS and BIG-IP Next CNF/Kubernetes nodes as a defense-in-depth measure against future undisclosed-vulnerability exploitation
CVEs associated with Vulnerability in F5 Products (CVE-2026-42015)
CVE-2026-42015
Timeline of Vulnerability in F5 Products (CVE-2026-42015)
- F5 identifies a long-term, previously undetected nation-state compromise of its own corporate network ("early August 2025" per Unit 42), affecting product development and engineering systems.
- CISA issues Emergency Directive ED 26-01 ordering federal agencies to inventory, harden, and patch F5OS, BIG-IP (TMOS), BIG-IP Next, BIG-IQ, and BNK/CNF instances given the risk that stolen source code and vulnerability data enable targeted exploit development.
- F5 publicly discloses the nation-state compromise; the actor is confirmed to have exfiltrated BIG-IP source code, information on undisclosed vulnerabilities, and implementation/configuration data for a subset of customers.
- ED 26-01 deadline for federal agencies to apply the latest patches to critical F5OS, BIG-IP TMOS, BIG-IQ, and BNK/CNF systems.
- HKCERT publishes a bulletin covering a separate batch of F5 BIG-IP Next CNF/Kubernetes/SPK/DNS vulnerabilities (CVE-2026-33278, CVE-2026-34986, CVE-2026-42959) with denial-of-service and remote-code-execution impact, on an overlapping product/version set to this alert.
- CISA adds an unrelated, actively-exploited critical F5 BIG-IP APM OAuth-server heap-overflow RCE (CVE-2026-94127, CVSS 9.8) to its Known Exploited Vulnerabilities catalog, underscoring active exploitation elsewhere in the F5 product line in the same week.
- F5 states software updates and mitigations for the affected versions are already available at the time of disclosure.
- GovCERT.HK/HKCERT issues Security Alert A26-09-38 for CVE-2026-42015, citing F5 Advisory K000163397, affecting BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS, F5OS-A, and F5OS-C with denial-of-service and tampering impact.
- Research analysis finds that CVE-2026-42015, as registered in NVD and Tenable, actually describes an unrelated GnuTLS PKCS#12 bounds-check flaw (CWE-193) affecting Red Hat products, not the F5 vulnerability cited by HKCERT/F5 — flagged as a likely CVE-ID citation error pending vendor clarification.
Sources cited for Vulnerability in F5 Products (CVE-2026-42015)
- Security Alert (A26-09-38): Vulnerability in F5 Products
- F5 Security Advisory K000163397
- MITRE CVE-2026-42015
- CVE-2026-42015 Detail (NVD) — registered as an unrelated GnuTLS PKCS#12 flaw
- CVE-2026-42015 (Tenable CVE database) — GnuTLS PKCS#12 bounds-check error, CWE-193
- CISA Known Exploited Vulnerabilities Catalog (CVE-2026-42015 absent as of 2026-09-25)
- HKCERT Security Bulletin: F5 Products Multiple Vulnerabilities
- Threat Brief: Nation-State Threat Actor Steals F5 Source Code and Undisclosed Vulnerabilities
- ED 26-01: Mitigate Vulnerabilities in F5 Devices
- Confirmed compromise of F5 network
- F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
- CISA Adds Four Known Exploited Vulnerabilities to Catalog
More in vulnerability
- Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK A26-09-37)
- Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40
- Critical ServiceNow AI Platform Vulnerabilities: Unauthenticated SQL Injection and Authorization Bypasses (CVE-2026-13016, CVE-2026-86857-86860)
- Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin skip_block_zeroing residual block reuse
Detection coverage for TL-2026-2660
As of 2026-09-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2660 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.