CVE-2026-59762: 
F5 BIG-IP Virtual Edition (tier - best) Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-59762 is a denial-of-service vulnerability in F5 BIG-IP and BIG-IP Next products caused by uncontrolled memory resource consumption when an HTTP/2 profile is configured on a virtual server. Undisclosed requests trigger excessive memory utilization in the Traffic Management Microkernel (TMM) process, degrading system performance until TMM is restarted. Affected products include BIG-IP (versions 17.1.0–17.1.3.4, 17.5.0–17.5.1.8, 21.0.0–21.0.0.3, 21.1.0–21.1.0.1), BIG-IP Next for Kubernetes (2.0.0–2.2.3, 2.3.0–2.3.2), BIG-IP Next SPK (1.7.0–1.7.18, 1.9.0+), and BIG-IP Next CNF (1.1.0–1.4.3, 2.0.0–2.2.3, 2.3.0–2.3.2). The vulnerability was published on July 15, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, F5 Advisory).

Détails techniques

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), where the BIG-IP HTTP/2 processing code fails to impose adequate restrictions on memory allocation when handling certain undisclosed request patterns. An unauthenticated, remote attacker can send specially crafted HTTP/2 requests to a virtual server with an HTTP/2 profile enabled, causing the TMM process to progressively consume memory without releasing it. This is a data plane issue only — the control plane is not exposed, meaning administrative interfaces are not directly at risk. No authentication or user interaction is required, and the attack can be automated, making it particularly accessible to threat actors (GitHub Advisory, F5 Advisory).

Impact

Successful exploitation causes progressive memory exhaustion in the TMM process, leading to degraded system performance and ultimately a denial-of-service condition on the BIG-IP system. The impact is limited to availability — there is no confidentiality or integrity impact, and no lateral movement or data exfiltration risk is associated with this vulnerability. Service disruption persists until the TMM process is forcibly or manually restarted, potentially causing extended outages for traffic passing through affected virtual servers (GitHub Advisory, F5 Advisory).

Exploitabilité

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at the time of publication. The EPSS score is approximately 0.33–0.46%, indicating a low near-term exploitation probability. The attack is classified as automatable (no user interaction required), which lowers the barrier for opportunistic exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the available data (GitHub Advisory, F5 Advisory).

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing F5 BIG-IP systems using tools such as Shodan or Censys, filtering for systems presenting HTTP/2 on virtual server endpoints. Confirm the target is running an affected version (e.g., BIG-IP 17.1.x before 17.1.3.4, 17.5.x before 17.5.1.8, 21.0.x before 21.0.0.3, or 21.1.x before 21.1.0.1).
  2. Confirm HTTP/2 profile: Attempt an HTTP/2 connection to the target virtual server to verify that an HTTP/2 profile is active (e.g., using curl --http2 or nghttp).
  3. Send crafted HTTP/2 requests: Transmit undisclosed request patterns (specific request structure not publicly known) over HTTP/2 to the target virtual server. The requests trigger abnormal memory allocation within the TMM process without proper release.
  4. Sustain the attack: Continuously send requests to maintain memory pressure, causing progressive memory exhaustion and system performance degradation.
  5. Achieve DoS: The TMM process becomes resource-starved, causing service disruption for all traffic handled by the affected virtual server until an administrator manually restarts the TMM process (GitHub Advisory, F5 Advisory).

Indicateurs de compromis

  • Network: Sustained or high-volume HTTP/2 traffic directed at BIG-IP virtual server endpoints from unexpected or unknown source IPs; unusual HTTP/2 connection patterns (e.g., high request rates without corresponding legitimate application traffic).
  • System Performance: Steadily increasing memory utilization on the TMM process observable via BIG-IP management dashboards or tmsh show sys performance commands; system alerts or SNMP traps related to memory thresholds being exceeded.
  • Logs: BIG-IP system logs (/var/log/ltm) showing TMM memory warnings or OOM-related messages; logs indicating TMM process restarts or crashes correlated with inbound HTTP/2 traffic spikes.
  • Process: TMM process exhibiting abnormally high and growing memory consumption without a corresponding increase in legitimate traffic load; repeated unplanned TMM restarts.

Atténuation et solutions de contournement

F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1; BIG-IP Next for Kubernetes 2.2.3 and 2.3.2; BIG-IP Next SPK 1.7.18; and BIG-IP Next CNF 1.4.3, 2.2.3, and 2.3.2. As a workaround prior to patching, administrators should consider removing or restricting HTTP/2 profiles from virtual servers where not strictly required, implementing network-level rate limiting or request filtering for HTTP/2 connections, and monitoring TMM memory utilization closely. Upgrading to a patched version is the recommended long-term remediation (F5 Advisory, GitHub Advisory).

Réactions de la communauté

The vulnerability received coverage from multiple cybersecurity news outlets including CyberSecurityNews and SecurityOnline, with articles highlighting the memory exhaustion risk to BIG-IP deployments (CyberSecurityNews). Field Effect and The Hacker News included it in weekly security roundups, indicating moderate industry attention (Field Effect Blog, The Hacker News). A Reddit thread in r/sysadmin discussed the vulnerability, reflecting practitioner-level awareness among BIG-IP administrators. CISA included it in its weekly vulnerability bulletin (SB26-201), signaling relevance to government and critical infrastructure operators (CISA Bulletin).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté F5 BIG-IP Virtual Edition (tier - best) Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-94127CRITICAL9.3
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
OuiOuiSep 22, 2026
CVE-2026-66842HIGH8.7
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiSep 02, 2026
CVE-2026-59762HIGH8.7
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiJul 15, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiMay 13, 2026
CVE-2026-63020LOW2.3
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiSep 02, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités