F5 Security Update – 23 June 2026

F5 has released a security update to address multiple PostgreSQL vulnerabilities that affect BIG-IP Next for Kubernetes.

The addressed vulnerabilities could allow the attacker to execute arbitrary code as the operating system user running the database.

Sample of the addressed vulnerabilities:

PostgreSQL Missing Validation of Multibyte Character Length Executes Arbitrary Code Vulnerability (CVE-2026-2006):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Remote Code Execution
Vulnerabilities
  • CVE-2026-2006
  • CVE-2026-2005
  • CVE-2026-2004
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Also, coordinate with vendors using the referenced third-party component to assess and confirm their exposure to the identified vulnerability.

F5 Security Update

References