Junglewise Threat Intelligence

CVE-2026-41218: F5 BIG-IP TMM use-after-free in PEM iRules

CVE-2026-41218 · Severity: high · CVSS 7.5 · Published 2026-05-13

Executive brief

A vulnerability in F5 BIG-IP devices can allow an attacker to crash the system's core traffic processing engine. This affects devices configured with specific Policy Enforcement Manager (PEM) rules used for traffic classification and analytics. An exploit would result in a complete service outage, preventing the device from handling network traffic and potentially disrupting business operations.

Technical details

This vulnerability is classified as a Use-After-Free (CWE-416) within the Traffic Management Microkernel (TMM) of F5 BIG-IP. It is triggered when specific PEM iRules are configured on a virtual server, specifically those utilizing commands such as CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, or urlcatquery. A remote, unauthenticated attacker can send specially crafted network traffic to the affected virtual server to cause TMM to terminate, resulting in a denial-of-service (DoS). The issue affects multiple BIG-IP modules including PEM, LTM, AFM, and APM across versions 16.1.x, 17.5.x, and 21.0.0. F5 has released a vendor advisory with mitigation and patching information.

Affected products

  • F5 BIG-IP PEM 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP APM 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP AFM 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP LTM 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability advisory

References

Related threats