F5 (9 Oct): four advisories for flaws in bundled third-party code (GnuTLS, Python protobuf, Apache Tomcat AJP) affecting BIG-IP 17.1, 17.5 and 21.1, BIG-IP Next CNF and BIG-IP Next for Kubernetes 2.2, and F5 Insight; denial of service and authentication bypass
F5 published four security advisories on 9 October 2026 (K000163593, K000163594, K000163606 and K000163608) for vulnerabilities in third-party components shipped inside its products. Hong Kong's GovCERT summarised the affected range as BIG-IP (all modules) 17.1.0 to 17.1.3, 17.5.0 to 17.5.1 and 21.1.0; BIG-IP Next CNF and BIG-IP Next for Kubernetes 2.2.0 to 2.2.1; and F5 Insight 1.0.0 to 1.1.0, with possible outcomes of denial of service, privilege escalation or bypassing security restrictions. The CVEs are: CVE-2026-78383, an Apache Tomcat AJP bug where an unauthenticated request with a missing body ties up a processing thread (CVSS 3.1 7.5; K000163606, which covers BIG-IP); CVE-2026-42009, a GnuTLS DTLS packet-reordering denial of service (7.5); CVE-2026-42010, a GnuTLS RSA-PSK bug where a username containing a NUL character matches a shorter username, allowing an authentication bypass (7.1); and CVE-2026-0994, a Python protobuf ParseDict recursion-limit bypass that causes denial of service (CVSS 4.0 8.2). The individual F5 articles say which product line each CVE affects. GovCERT says updates and mitigations are available, but Tenable's BIG-IP check for K000163606 notes that F5 had not yet listed a fixed BIG-IP release for the Tomcat issue. No exploitation has been reported. Primary: GovCERT.HK alert A26-10-15 summarising the F5 advisories.
- Product
- F5 BIG-IP (all modules), BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5 Insight
- Versions
- BIG-IP 17.1.0–17.1.3, 17.5.0–17.5.1, 21.1.0; BIG-IP Next CNF 2.2.0–2.2.1; BIG-IP Next for Kubernetes 2.2.0–2.2.1; F5 Insight 1.0.0–1.1.0 (per GovCERT.HK; product-to-CVE mapping in each F5 article)
- CVSS
- CVE-2026-0994 8.2 (CVSS 4.0, Google CNA); CVE-2026-42009 7.5; CVE-2026-78383 7.5; CVE-2026-42010 7.1 (CVSS 3.1)
- Exploited in Australia?
- unknown
- Patch to
- Check each F5 article (K000163593, K000163594, K000163606, K000163608) for fixed releases and mitigations for your product line; where BIG-IP has no fixed release yet for the Tomcat AJP issue (K000163606), keep the management interface and AJP-facing services off untrusted networks
Primary: GovCERT.HK — Security Alert (A26-10-15): Multiple vulnerabilities in F5 products (9 Oct 2026) · Vendor: F5 — K000163606: Apache Tomcat vulnerability CVE-2026-78383 (see also K000163593, K000163594, K000163608) · CVE: CVE-2026-78383, CVE-2026-42009, CVE-2026-42010, CVE-2026-0994 · Tenable — F5 Networks BIG-IP: Apache Tomcat vulnerability (K000163606) check
