logo

New BIG-IP Next Central Manager bugs allow device takeover

ID: 0fc96aa1-0059-555d-b27b-5da9d710d6a0

STIX ID: report--0fc96aa1-0059-555d-b27b-5da9d710d6a0

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-05-08

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

F5 patched two high-severity vulnerabilities in BIG-IP Next Central Manager (CVE-2024-26026 and CVE-2024-21793) that permit unauthenticated remote SQL/OData injection leading to full administrative takeover and creation of hidden rogue accounts on managed BIG-IP Next assets; Eclypsium published a PoC and recommends patching or restricting access, and F5 advises applying updates or limiting management UI access as a temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.