---
schema: 1
kind: vulnerability
title: "CVE-2026-41225 — F5 BIG-IP / BIG-IQ: iControl REST Manager-role authenticated RCE (CVSS 4.0 score 8.6 / CVSS 3.1 score 9.1) leading the May 2026 Quarterly Notification"
headline: "CVE-2026-41225 — F5 BIG-IP / BIG-IQ: iControl REST Manager-role authenticated RCE (CVSS 4.0 score 8.6 / CVSS 3.1 score 9.1) leading the May 2026 Quarterly"
summary: "F5 BIG-IP / BIG-IQ May 2026 Quarterly Notification — SecurityWeek reports \"over 19 high-severity and 32 medium-severity\" bugs across BIG-IP, BIG-IQ and NGINX; NCSC-NL CSAF lists 43 in the BIG-IP / BIG-IQ scope. Lead CVE-2026-41225 (CVSS 4.0 score 8.6 per F5 / SecurityWeek; CVSS 3.1 score 9.1 per NCSC-NL / NVD; both confirm post-auth Manager-role RCE on iControl REST); secondary 8.7-class cluster includes iControl REST command injection, SSH-password exposure in audit logs, and Appliance-mode-bypass privilege escalation. No in-the-wild exploitation reported as of advisory publication. Affects BIG-IP appliances widely deployed across European public-sector load-balancing / WAF perimeters (F5 K000160932, 2026-05-14; SecurityWeek, 2026-05-14)."
discovered_at: "2026-05-17T05:00:02Z"
event_date: 2026-05-15
run_id: 2026-05-17-4381863a
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - priv-esc
  - patch-available
regions:
  - global
sectors:
  - public-sector
  - finance
  - telco
  - technology
entities: []
cves:
  - id: CVE-2026-41225
    cvss: "8.6"
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
sources:
  - url: "https://my.f5.com/manage/s/article/K000160932"
    publisher: "F5 K000160932, 2026-05-14"
    role: primary
  - url: "https://www.securityweek.com/f5-patches-over-50-vulnerabilities/"
    publisher: "SecurityWeek, 2026-05-14"
    role: corroborating
  - url: "https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0162.json"
    publisher: "NCSC-NL NCSC-2026-0162, 2026-05-15"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Apply the F5 BIG-IP / BIG-IQ May 2026 Quarterly Notification across all internet-or-management-network-reachable F5 appliances** within standard change windows, and rotate every Manager-role iControl REST credential at the same time. CVE-2026-41225 is post-auth Manager-role only, but the practical attack chain is *credential theft → iControl REST object creation → shell execution*, so credential rotation is the operationally critical companion to the patch. Reference: § 2 F5 item."
migrated_from: briefs/2026-05-17.md
---

F5 published its May 2026 Quarterly Security Notification on 2026-05-14. SecurityWeek's article describes the scope as *"over 19 high-severity and 32 medium-severity vulnerabilities impacting BIG-IP, BIG-IQ, and NGINX"* — summing to 51-plus across the F5 product family; NCSC-NL's CSAF restatement (NCSC-2026-0162) lists 43 CVEs in the BIG-IP / BIG-IQ scope (NGINX bugs counted separately). The affected components span iControl REST, iControl SOAP, the TMOS Shell, Traffic Management Microkernel (TMM), the Configuration utility, Advanced WAF, ASM, PEM, DNS, APM, and SSL Orchestrator ([F5 K000160932, 2026-05-14](https://my.f5.com/manage/s/article/K000160932); [SecurityWeek, 2026-05-14](https://www.securityweek.com/f5-patches-over-50-vulnerabilities/); [NCSC-NL NCSC-2026-0162, 2026-05-15](https://advisories.ncsc.nl/csaf/v2/2026/ncsc-2026-0162.json)). The lead issue is CVE-2026-41225 — F5 / SecurityWeek score it CVSS 4.0 base 8.6 HIGH; NVD and NCSC-NL also publish a CVSS 3.1 base score of 9.1 CRITICAL for the same CVE (the v3.1/v4.0 scale difference, not a vendor disagreement on severity). [CWE-648](https://cwe.mitre.org/data/definitions/648.html) Incorrect Use of Privileged APIs (per NVD); NVD verbatim: *"A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands"* — an authenticated RCE via the iControl REST `/mgmt/tm/` API, exploitable by any principal holding the Manager RBAC role. The CVSS-8.7 secondary cluster covers iControl REST command injection (CVE-2026-42930, CVE-2026-42924, CVE-2026-42406, CVE-2026-41953), SSH-password leakage in audit log / API response bodies (CVE-2026-40698), and privilege escalation via misconfigured permissions (CVE-2026-40631, CVE-2026-40061, CVE-2026-34176). The exploitation prerequisite is authenticated Manager-role network access to the BIG-IP management port or self-IP addresses — once present, the attacker can also bypass Appliance mode restrictions designed as a hardening boundary. No exploitation in the wild reported as of advisory publication. **Why it matters to us:** the operationally significant chain is *initial-access-by-credential-theft → iControl-REST-object-creation → shell command execution under the BIG-IP control plane*. SOCs should monitor iControl REST audit logs for POST/PATCH requests creating unexpected configuration objects from Manager-role principals; alert on TMSH commands spawning shell subprocesses outside change-windows; restrict iControl REST reachability to jump hosts on management-only VLANs; rotate every Manager-role credential as the May 2026 quarterly is rolled out; disable iControl SOAP entirely where unused. Separately, the previously-covered CVE-2026-42945 NGINX heap overflow is rolled into F5's quarterly scope but is not re-reported here.
