CVE-2026-42406
High
Published: 13 May 2026
Published
13 May 2026
Modified
13 May 2026
KEV Added
—
Patch
—
CVSS Score
8.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
EPSS Score
0.0003
7.7th percentile
Risk Priority
17
60% EPSS · 20% KEV · 20% CVSS
Summary
CVE-2026-42406 is a high-severity Privilege Defined With Unsafe Actions (CWE-267) vulnerability. Its CVSS base score is 8.7 (High).
Operationally, ranked at the 7.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
NVD Description
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support…
more
(EoTS) are not evaluated.
Deeper analysisAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)
Affected Products
—
Software
inferred from references and description; NVD did not file a CPE for this CVE