CVE-2026-32643
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVSS 4.0
- 8.5 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.16% probability · 5th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-250
- Affected
- f5/big-ip access policy manager · f5/big-ip advanced firewall manager · f5/big-ip advanced web application firewall · f5/big-ip analytics · f5/big-ip application acceleration manager · f5/big-ip application security manager · f5/big-ip application visibility and reporting · f5/big-ip automation toolchain · f5/big-ip carrier-grade nat · f5/big-ip container ingress services · f5/big-ip ddos hybrid defender · f5/big-ip domain name system · f5/big-ip edge gateway · f5/big-ip fraud protection service · f5/big-ip global traffic manager · f5/big-ip link controller · f5/big-ip local traffic manager · f5/big-ip policy enforcement manager · f5/big-ip ssl orchestrator · f5/big-ip webaccelerator · +2 more
- Source
- f5sirt@f5.com
References
- https://my.f5.com/manage/s/article/K000160972Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.