F5 Security Update – 20 May 2026

F5 has released a security update to address a vulnerability across F5 NGINX JavaScript (njs).

The addressed vulnerability could allow the remote attacker to perform denial of service (DoS) attacks on the NGINX system, or to possibly trigger code execution.

The addressed vulnerability:

NGINX ngx_Http_Js_Module Denial of Service Vulnerability (CVE-2026-8711):

  • CVSS: 8.1
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service
Vulnerabilities

CVE-2026-8711

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

F5 Security Advisory

References