Junglewise Threat Intelligence

CVE-2026-40060: F5 BIG-IP Advanced WAF and ASM denial of service in bd process

CVE-2026-40060 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: F5 BIG-IP Advanced WAF. Vendors: F5.

Executive brief

A vulnerability in F5 BIG-IP security products can allow an attacker to crash a critical system process by sending specific network requests. This affects the Advanced Web Application Firewall (WAF) and Application Security Manager (ASM) modules, which are used to protect web applications from cyberattacks. If exploited, the security service may become unavailable, potentially leaving applications unprotected or causing a disruption in network traffic.

Technical details

A denial-of-service vulnerability exists in the F5 BIG-IP Advanced WAF and ASM modules due to an unchecked return value (CWE-252) during the processing of specific network requests. When a security policy is active on a virtual server, an unauthenticated attacker can send undisclosed requests that cause the 'bd' (the main enforcement engine) process to terminate. This results in a service disruption for the affected virtual server. The vulnerability affects multiple versions across the 16.x, 17.x, and 21.x branches. F5 has released updates for several versions, including 17.5.1.4, 17.1.3.1, and 21.0.0.1, to address the issue.

Affected products

  • F5 BIG-IP Advanced WAF 17.5.0 - 17.5.1, 17.1.0 - 17.1.3, 16.1.0 - 16.1.6, 21.0.0
  • F5 BIG-IP ASM 17.5.0 - 17.5.1, 17.1.0 - 17.1.3, 16.1.0 - 16.1.6, 21.0.0

Timeline

  • 2026-05-13: advisory: Initial advisory published by F5 Networks

References

Related threats