Canada warns of flaws in Forcepoint, F5 and Cisco security products
The Canadian Centre for Cyber Security issued a cluster of alerts about vulnerabilities in three security products: Forcepoint's firewall, F5's BIG-IP APM access gateway and Cisco's ISE identity platform. F5 and Cisco confirmed active exploitation of some flaws, and Cisco says no workarounds fully resolve the issues.
- Forcepoint NGFW (CVE-2026-12974): security-policy bypass, no confirmed exploitation
- F5 BIG-IP APM (CVE-2026-94127): remote code execution, exploited in the wild
- Cisco ISE (CVE-2026-76460): auth bypass and admin access, actively exploited
- Cisco says no workarounds exist — fixed software must be installed
Read next
Security