F5 Product Security Update Advisory (CVE-2024-26026)

Overview

 

We have released updates to fix vulnerabilities in F5 products. users of affected versions are advised to update to the latest version.

 

Affected Products

 

BIG-IP Next Central Manager versions: 20.0.1 (inclusive) to 20.1.0 (inclusive)

 

Resolved Vulnerabilities

 

SQL Injection Vulnerability in BIG-IP Next Central Manager (CVE-2024-26026)

 

Vulnerability Patches

 

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

BIG-IP Next Central Manager 20.2.0 version

 

Referenced Sites

 

[1] CVE-2024-26026 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-26026

[2] K000138733: BIG-IP Next Central Manager SQL Injection vulnerability CVE-2024-26026

https://my.f5.com/manage/s/article/K000138733