Junglewise Threat Intelligence

CVE-2026-40423: F5 BIG-IP denial of service in TMM SIP profile processing

CVE-2026-40423 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager. Vendors: F5.

Executive brief

F5 BIG-IP devices, which manage and secure enterprise network traffic, are vulnerable to a denial-of-service attack when processing specific Session Initiation Protocol (SIP) traffic. An attacker can send specially crafted network traffic to a virtual server, causing the core traffic management component to crash. This results in a complete interruption of network services and application availability managed by the affected BIG-IP system.

Technical details

This vulnerability is classified as a resource management issue (CWE-770) within the Traffic Management Microkernel (TMM) of F5 BIG-IP. When a virtual server is configured with a SIP (Session Initiation Protocol) profile, it fails to properly handle specific, undisclosed network traffic. A remote, unauthenticated attacker can exploit this by sending malicious SIP packets, leading to a TMM crash and subsequent denial of service. The vulnerability affects multiple BIG-IP modules including LTM, AFM, and APM across versions 16.1.x, 17.5.x, and 21.0.0. F5 has released a vendor advisory (K000161023) detailing affected versions and potential mitigations.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Application Security Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability advisory.

References

Related threats