Junglewise Threat Intelligence

CVE-2026-39458: F5 BIG-IP TMM denial of service in DNS cache profile

CVE-2026-39458 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 Big-Ip Advanced Firewall Manager, F5 BIG-IP DNS. Vendors: F5.

Executive brief

F5 BIG-IP is a suite of networking devices used to manage and secure enterprise web traffic. A vulnerability in the DNS caching feature allows a remote attacker to send specific network traffic that crashes the system's core processing engine. This results in a complete service outage, preventing legitimate users from accessing applications protected or managed by the affected BIG-IP device.

Technical details

A denial-of-service vulnerability exists in F5 BIG-IP when a DNS profile with DNS cache is enabled on a virtual server. The issue is rooted in an 'Access of Uninitialized Pointer' (CWE-824) within the Traffic Management Microkernel (TMM). A remote, unauthenticated attacker can send undisclosed network traffic to the virtual server, triggering a TMM crash and subsequent system restart. This affects multiple BIG-IP modules including DNS, LTM, AFM, and APM across versions 16.1.x, 17.5.x, and 21.0.0. F5 has released advisory K000160945 to address the issue.

Affected products

  • F5 BIG-IP DNS 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability advisory

References

Related threats