Junglewise Threat Intelligence

CVE-2026-40618: F5 BIG-IP TMM denial of service in SSL profile processing

CVE-2026-40618 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: F5 Big-Ip Access Policy Manager, F5 Big-Ip Advanced Firewall Manager, F5 BIG-IP, F5 Big-Ip Local Traffic Manager, F5 BIG-IP Advanced WAF. Vendors: F5.

Executive brief

A vulnerability in F5 BIG-IP networking devices can allow an attacker to crash the system's core traffic processing engine. This affects devices configured to handle secure (SSL) web traffic when certain hardware acceleration features are missing or disabled. An exploit would result in a complete service outage, preventing legitimate users from accessing applications protected by the BIG-IP system.

Technical details

A denial-of-service vulnerability exists in the F5 BIG-IP Traffic Management Microkernel (TMM). The issue occurs when an SSL profile is configured on a virtual server and the system is either a Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or a hardware platform with 'crypto.hwacceleration' disabled. An unauthenticated remote attacker can send specific, undisclosed network traffic that triggers an incorrect calculation of buffer size (CWE-131), leading to a TMM crash. This results in a restart of the traffic processing services and a temporary loss of availability. Fixed versions include updates to the 16.x and 17.x branches.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced WAF 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability advisory.

References

Related threats