Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS

Vulnerability in F5 Products (CVE-2026-42015) (TL-2026-2660), also tracked as A26-09-38, is a medium-severity software vulnerability, first published 2026-09-24. It has no confirmed attribution, affects F5, Inc. BIG-IP Next CNF, references 1 CVE (CVE-2026-42015), maps to 9 MITRE ATT&CK techniques (T1190, T1195, T1499.004), and is covered by 9 detection rules and 10 indicators of compromise.

Key facts for TL-2026-2660

Threat ID
TL-2026-2660
Also known as
A26-09-38
Severity
MEDIUM
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-24
Last reviewed
2026-09-24
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, technology, telecoms, critical-infrastructure
Target regions
Asia-Pacific, North America, Europe
Detection rules
9
Indicators of compromise
10

GovCERT.HK/HKCERT issued Security Alert A26-09-38 on 2026-09-24 for CVE-2026-42015, which F5 Advisory K000163397 states affects BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS, F5OS-A, and F5OS-C, with impact described as denial of service and tampering. No CVSS score, active-exploitation confirmation, or public PoC is stated, and F5 says updates/mitigations are already available. Independent verification found the CVE ID as registered in NVD and Tenable actually maps to an unrelated GnuTLS PKCS#12 flaw affecting Red Hat products — a discrepancy defenders should resolve with F5/HKCERT before relying on the ID alone.

How Vulnerability in F5 Products (CVE-2026-42015) works

GovCERT.HK (operating on behalf of HKCERT) published Security Alert A26-09-38 on 24 September 2026, forwarding an F5 vendor advisory (K000163397) for CVE-2026-42015. Per the alert, the vulnerability affects BIG-IP Next CNF versions 1.4.0-1.4.2, BIG-IP Next for Kubernetes versions 2.2.0-2.2.2 and 2.3.0, F5OS version 2.0.0, F5OS-A versions 1.5.1-1.5.4 and 1.8.0-1.8.4, and F5OS-C versions 1.6.0-1.6.4 and 1.8.0-1.8.2. The stated impact of successful exploitation is denial of service and tampering on an affected system. Neither the alert nor any source located during this research states a CVSS score, an attack vector (network vs. local, authentication requirement), a root-cause/CWE classification, evidence of a public proof-of-concept, or evidence of active in-the-wild exploitation. F5's advisory states software updates and mitigations for the affected versions were already available at the time of disclosure; F5's own knowledge-base article (my.f5.com, article K000163397) could not be retrieved directly in this research pass because the portal renders its advisory body client-side and returned no substantive content to automated fetches — the technical detail on affected-fix versions and any workaround therefore rests on the HKCERT re-publication rather than the primary F5 text.

IMPORTANT SOURCING CAVEAT: cross-checking CVE-2026-42015 against NVD's REST API and against Tenable's CVE database returned a completely different, unrelated vulnerability: an off-by-one bounds-check error in GnuTLS's PKCS#12 bag-element handling (CWE-193), which allows memory corruption when appending to a bag already containing 32 elements, scored CVSS v3.1 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) and affecting Red Hat Enterprise Linux 7-10 and related products (GnuTLS Security Advisory GNUTLS-SA-2026-04-29-11, Red Hat Bugzilla #2467678, RHSA-2026 series advisories). This record has no relationship to F5, BIG-IP, F5OS, or Kubernetes. Because CVE identifiers are meant to be uniquely assigned by a single CNA, this is very unlikely to be a legitimate shared ID — it is far more consistent with a citation/typo error either in F5's own advisory K000163397 or in HKCERT's transcription of it (the correct F5-side CVE for this product/version/impact combination could not be independently located under a different number during this research pass — the affected-product fingerprint does not match any other September 2026 F5 CVE found, including the CVE-2026-33278 / CVE-2026-34986 / CVE-2026-42959 batch HKCERT published on 2026-09-02 for an overlapping BIG-IP Next CNF/Kubernetes/SPK/DNS product set). CVE-2026-42015 is also absent from the CISA Known Exploited Vulnerabilities catalog as of 2026-09-25, consistent with either identifier. Analysts should treat the product/version/impact facts from the HKCERT alert as reliable (they are corroborated internally and match the hunt-phase source), but should NOT pull CVSS, CWE, or technical root-cause detail for CVE-2026-42015 from NVD/Tenable/vulnerability-database tooling, since that data belongs to the unrelated GnuTLS issue — verify the true identifier directly with F5 support before scoring or ticketing this item by CVE number alone.

This disclosure lands in an elevated-risk period for F5 products. In August 2025 F5 identified a long-term, previously undetected compromise of its own corporate network by a nation-state actor, publicly disclosed 15-16 October 2025; the actor exfiltrated BIG-IP source code, information on undisclosed vulnerabilities, and implementation/configuration data for a subset of customers from an internal knowledge-management platform (Unit 42; NCSC UK). CISA responded with Emergency Directive ED 26-01, ordering federal agencies to inventory all BIG-IP (F5OS), BIG-IP (TMOS), BIG-IP Virtual Edition, BIG-IP Next, BIG-IQ, and BNK/CNF instances, check whether management interfaces are internet-exposed, and patch critical systems by 22 October 2025 and remaining devices by 31 October 2025 — the same product family named in this alert. F5 subsequently accelerated its disclosure cadence (45 vulnerabilities in the quarter following the breach vs. 6 the prior quarter), and the pattern has continued through 2026: an out-of-band notification on 2 September 2026 covered further BIG-IP Next CNF/Kubernetes/SPK/DNS issues (CVE-2026-33278, CVE-2026-34986, CVE-2026-42959, DoS and RCE impact), and a separate, unrelated critical BIG-IP APM OAuth-server heap-overflow RCE (CVE-2026-94127, CVSS 9.8) was confirmed under active exploitation and added to the CISA KEV catalog on 22 September 2026 — two days before this alert. Because the threat actor behind the 2025 breach retains stolen BIG-IP source code and undisclosed-vulnerability knowledge that CISA assessed can be used to "develop targeted exploits," any newly disclosed F5 vulnerability in this window carries elevated scrutiny even absent independent confirmation of active exploitation for this specific CVE.

Architecturally, BIG-IP Next CNF and BIG-IP Next for Kubernetes are F5's containerized, cloud-native network functions built to run on Kubernetes/OpenShift for telco, 5G, and cloud-edge traffic-processing use cases, while F5OS (and its F5OS-A/F5OS-C variants) is the base operating system F5 ships on its rSeries/iSeries hardware appliances and that underlies BIG-IP Next deployments. A denial-of-service-and-tampering flaw in this layer therefore has the potential to affect inline, traffic-processing network functions and/or the host OS layer beneath a BIG-IP Next fleet rather than a peripheral management tool, which is consistent with the MEDIUM severity assessment in the absence of a stated CVSS score, RCE, or data-disclosure impact.

Remediation: apply F5's published fix for the affected BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS, F5OS-A, and F5OS-C versions per Advisory K000163397 as soon as operationally feasible; confirm whether management interfaces on these devices are internet-exposed and remediate per the same guidance CISA issued in ED 26-01 for this product family; and independently verify the correct CVE identifier with F5 support given the CVE-2026-42015/GnuTLS collision documented above before using the ID in scanning, ticketing, or KEV/NVD-driven prioritization tooling.

MITRE ATT&CK techniques used in TL-2026-2660

Initial Access

T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise

Impact

T1499.004 Application or System Exploitation; T1565 Data Manipulation

Resource Development

T1587.004 Exploits; T1588.006 Vulnerabilities

Reconnaissance

T1592.002 Software; T1595.002 Vulnerability Scanning

Defense Impairment

T1601 Modify System Image

Affected products and versions in Vulnerability in F5 Products (CVE-2026-42015)

  • F5, Inc. — BIG-IP Next CNF
    Vulnerable versions: 1.4.0-1.4.2
    Fixed in: See F5 Advisory K000163397 for the specific fixed release
  • F5, Inc. — BIG-IP Next for Kubernetes
    Vulnerable versions: 2.2.0-2.2.2; 2.3.0
    Fixed in: See F5 Advisory K000163397 for the specific fixed release
  • F5, Inc. — F5OS
    Vulnerable versions: 2.0.0
    Fixed in: See F5 Advisory K000163397 for the specific fixed release
  • F5, Inc. — F5OS-A
    Vulnerable versions: 1.5.1-1.5.4; 1.8.0-1.8.4
    Fixed in: See F5 Advisory K000163397 for the specific fixed release
  • F5, Inc. — F5OS-C
    Vulnerable versions: 1.6.0-1.6.4; 1.8.0-1.8.2
    Fixed in: See F5 Advisory K000163397 for the specific fixed release

Remediation for Vulnerability in F5 Products (CVE-2026-42015)

Patches

  • F5 Advisory K000163397 (software updates/mitigations for the affected BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS, F5OS-A, F5OS-C versions were stated as available at disclosure)

Immediate actions

  • Apply the F5 fix for the affected BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS, F5OS-A, and F5OS-C versions referenced in Advisory K000163397
  • Inventory all in-scope F5OS/BIG-IP Next/BNK-CNF instances and confirm whether their management interfaces are internet-accessible, per the exposure check CISA directed for this exact product family in ED 26-01
  • Independently confirm the correct CVE identifier for this fix with F5 support before using CVE-2026-42015 in scanner/ticketing/KEV-driven prioritization workflows, given the documented ID collision with an unrelated GnuTLS CVE

Workarounds

  • No vendor-published interim workaround beyond patching was found in the sources reviewed; consult F5 Advisory K000163397 directly for any interim mitigation guidance not captured by automated retrieval of the my.f5.com portal

Longer-term hardening

  • Track F5's accelerated post-breach disclosure cadence and CISA KEV additions for the BIG-IP/F5OS/BIG-IP Next product family given the 2025 nation-state theft of BIG-IP source code and undisclosed-vulnerability data
  • Enable F5 event streaming to SIEM and apply F5's fleet hardening guidance across BIG-IP Next Central Manager-managed deployments
  • Restrict and monitor administrative/management-plane access to F5OS and BIG-IP Next CNF/Kubernetes nodes as a defense-in-depth measure against future undisclosed-vulnerability exploitation

CVEs associated with Vulnerability in F5 Products (CVE-2026-42015)

CVE-2026-42015

Timeline of Vulnerability in F5 Products (CVE-2026-42015)

  • F5 identifies a long-term, previously undetected nation-state compromise of its own corporate network ("early August 2025" per Unit 42), affecting product development and engineering systems.
  • CISA issues Emergency Directive ED 26-01 ordering federal agencies to inventory, harden, and patch F5OS, BIG-IP (TMOS), BIG-IP Next, BIG-IQ, and BNK/CNF instances given the risk that stolen source code and vulnerability data enable targeted exploit development.
  • F5 publicly discloses the nation-state compromise; the actor is confirmed to have exfiltrated BIG-IP source code, information on undisclosed vulnerabilities, and implementation/configuration data for a subset of customers.
  • ED 26-01 deadline for federal agencies to apply the latest patches to critical F5OS, BIG-IP TMOS, BIG-IQ, and BNK/CNF systems.
  • HKCERT publishes a bulletin covering a separate batch of F5 BIG-IP Next CNF/Kubernetes/SPK/DNS vulnerabilities (CVE-2026-33278, CVE-2026-34986, CVE-2026-42959) with denial-of-service and remote-code-execution impact, on an overlapping product/version set to this alert.
  • CISA adds an unrelated, actively-exploited critical F5 BIG-IP APM OAuth-server heap-overflow RCE (CVE-2026-94127, CVSS 9.8) to its Known Exploited Vulnerabilities catalog, underscoring active exploitation elsewhere in the F5 product line in the same week.
  • F5 states software updates and mitigations for the affected versions are already available at the time of disclosure.
  • GovCERT.HK/HKCERT issues Security Alert A26-09-38 for CVE-2026-42015, citing F5 Advisory K000163397, affecting BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS, F5OS-A, and F5OS-C with denial-of-service and tampering impact.
  • Research analysis finds that CVE-2026-42015, as registered in NVD and Tenable, actually describes an unrelated GnuTLS PKCS#12 bounds-check flaw (CWE-193) affecting Red Hat products, not the F5 vulnerability cited by HKCERT/F5 — flagged as a likely CVE-ID citation error pending vendor clarification.

Sources cited for Vulnerability in F5 Products (CVE-2026-42015)

More in vulnerability

Detection coverage for TL-2026-2660

As of 2026-09-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2660 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats