Junglewise Threat Intelligence

CVE-2026-40629: F5 BIG-IP denial of service in SSL-enabled virtual servers

CVE-2026-40629 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager. Vendors: F5.

Executive brief

A vulnerability in F5 BIG-IP systems can allow an attacker to crash the service responsible for handling web traffic. When specific SSL settings are enabled, specially crafted network traffic can cause the virtual server to stop accepting new connections from legitimate users. This results in a denial-of-service, potentially disrupting business operations and customer access to hosted applications.

Technical details

A resource management vulnerability (CWE-770) exists in F5 BIG-IP when SSL profiles are configured on a virtual server. An unauthenticated remote attacker can send undisclosed network traffic that triggers a failure in the virtual server's ability to process new client connections. The issue affects multiple BIG-IP modules including LTM, APM, and AFM, as well as BIG-IP Next products. F5 has released a vendor advisory (K000158978) detailing the affected versions and potential mitigations, though specific technical root causes of the 'undisclosed traffic' are not public.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1
  • F5 BIG-IP Next Cloud-Native Network Functions 1.4.0, 2.0.0 - 2.0.2
  • F5 BIG-IP Next Service Proxy for Kubernetes 1.7.0 - 1.7.15, 2.0.0 - 2.0.2

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory

References

Related threats