CVE-2026-42924: F5 BIG-IP Access Policy Manager
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
- F5 BIG-IP Access Policy Manager: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Advanced Firewall Manager: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Advanced Web Application Firewall: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Analytics: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Application Acceleration Manager: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Application Security Manager: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Application Visibility And Reporting: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Automation Toolchain: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Carrier-Grade Nat: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Container Ingress Services: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Ddos Hybrid Defender: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Domain Name System: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Edge Gateway: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Fraud Protection Service: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Global Traffic Manager: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Link Controller: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Local Traffic Manager: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Policy Enforcement Manager: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP SSL Orchestrator: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Webaccelerator: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
- F5 BIG-IP Websafe: version 21.0.0 only; from 17.1.0, up to and including 17.1.3; from 17.5.0, up to and including 17.5.1; from 16.1.0, up to and including 16.1.6
Published 2026-05-13. Last modified 2026-06-18.