PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-41959 F5 CVE debrief

CVE-2026-41959 is a HIGH-severity vulnerability affecting F5 BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and BIG-IP iControl REST. An authenticated attacker may exploit this vulnerability to view the network status of destination systems. The vulnerability has a CVSS score of 7.1 and was published on May 13, 2026. Multiple versions of BIG-IP and BIG-IQ are affected, including those that have reached End of Technical Support (EoTS).

Vendor
F5
Product
BIG-IP
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-13
Original CVE updated
2026-06-24
Advisory published
2026-05-13
Advisory updated
2026-06-24

Who should care

Organizations using F5 BIG-IP and BIG-IQ products should prioritize patching this vulnerability. Specifically, administrators of BIG-IP and BIG-IQ systems, security teams, and IT professionals responsible for network security and vulnerability management should take immediate action.

Technical summary

The vulnerability exists in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and BIG-IP iControl REST. An authenticated attacker with local access could potentially exploit this vulnerability to view the network status of destination systems. The Common Vulnerabilities and Exposures (CVE) score is 7.1, indicating a HIGH severity level. Multiple CPEs are affected across various versions of BIG-IP and BIG-IQ.

Defensive priority

Patching is the primary recommended action. Apply the necessary patches or updates provided by F5 to vulnerable BIG-IP and BIG-IQ systems as soon as possible.

Recommended defensive actions

  • Apply patches or updates provided by F5 to vulnerable BIG-IP and BIG-IQ systems.
  • Implement compensating controls, such as restricting access to TMOS Shell (tmsh) network diagnostics commands and monitoring for suspicious activity.
  • Conduct a thorough review of network configurations and user access to identify potential vulnerabilities.
  • Consider upgrading to versions of BIG-IP and BIG-IQ that are not vulnerable.
  • Monitor system logs and network traffic for signs of exploitation.

Evidence notes

The CVE record and NVD detail provide comprehensive information about the vulnerability, including affected versions and potential impacts. F5 has provided mitigation guidance through their support article.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-41959 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-41959

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-41959 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-41959

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.