Junglewise Threat Intelligence

CVE-2026-40067: F5 BIG-IP APM buffer overflow in apmd process

CVE-2026-40067 · Severity: high · CVSS 7.5 · Published 2026-05-13

Executive brief

F5 BIG-IP Access Policy Manager (APM) is a solution used to manage secure remote access to corporate applications. A vulnerability has been identified where specific network traffic can cause the system's policy management process to crash. This results in a denial-of-service, potentially preventing users from logging in or accessing protected resources.

Technical details

A classic buffer overflow (CWE-120) exists in the F5 BIG-IP APM 'apmd' process when an access policy is configured on a virtual server. The vulnerability is triggered by 'undisclosed traffic' and does not require authentication or user interaction. An attacker can exploit this to terminate the apmd process, leading to a denial-of-service (DoS) condition for access policy enforcement. F5 has released updates for several branches, including 21.0.0.1, 17.5.1.4, and 17.1.3.1, to address the issue.

Affected products

  • F5 BIG-IP Access Policy Manager 17.5.0 to 17.5.1, 17.1.0 to 17.1.3, 16.1.0 to 16.1.6, 21.0.0

Timeline

  • 2026-05-13: advisory: Initial advisory published by F5 Networks
  • 2026-05-13: disclosed

References

Related threats