Junglewise Threat Intelligence

CVE-2026-41956: F5 BIG-IP stack overflow in Traffic Management Microkernel

CVE-2026-41956 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager. Vendors: F5.

Executive brief

A vulnerability in F5 BIG-IP networking devices can allow an attacker to crash the system's core traffic processing engine. This affects devices configured to handle UDP traffic with specific classification profiles, potentially leading to a complete disruption of network services. Successful exploitation results in a denial-of-service condition, impacting business operations and connectivity.

Technical details

A stack-based buffer overflow (CWE-121) exists in the F5 Traffic Management Microkernel (TMM). The vulnerability is triggered when a classification profile is configured on a UDP virtual server and processes specific, undisclosed requests. An unauthenticated remote attacker can exploit this by sending malicious UDP packets to the affected virtual server, causing the TMM to terminate and resulting in a denial-of-service (DoS). The issue affects multiple BIG-IP modules including LTM, AFM, and APM across versions 16.x and 17.x, as well as BIG-IP Next products. F5 has provided mitigation and advisory information in article K000158038.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1
  • F5 BIG-IP Next Cloud-Native Network Functions 1.4.0, 2.0.0 - 2.0.2
  • F5 BIG-IP Next for Kubernetes 2.0.0

Timeline

  • 2026-05-13: advisory: Initial advisory published by F5

References

Related threats