CVE-2026-66842: F5 BIG-IP
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
- F5 BIG-IP: from 21.1.0, before 21.1.0.1 (fixed in 21.1.0.1); from 21.0.0, before 21.0.0.3 (fixed in 21.0.0.3); from 17.5.0, before 17.5.1.8 (fixed in 17.5.1.8); from 17.1.0, before 17.1.3.4 (fixed in 17.1.3.4)
- F5 BIG-IQ: from 8.4.0, before 8.4.2.1 (fixed in 8.4.2.1)
Published 2026-09-02. Last modified 2026-09-03.