CVE-2026-59762: 
F5 BIG-IP Virtual Edition (tier - best) 脆弱性の分析と軽減

概要

CVE-2026-59762 is a denial-of-service vulnerability in F5 BIG-IP and BIG-IP Next products caused by uncontrolled memory resource consumption when an HTTP/2 profile is configured on a virtual server. Undisclosed requests trigger excessive memory utilization in the Traffic Management Microkernel (TMM) process, degrading system performance until TMM is restarted. Affected products include BIG-IP (versions 17.1.0–17.1.3.4, 17.5.0–17.5.1.8, 21.0.0–21.0.0.3, 21.1.0–21.1.0.1), BIG-IP Next for Kubernetes (2.0.0–2.2.3, 2.3.0–2.3.2), BIG-IP Next SPK (1.7.0–1.7.18, 1.9.0+), and BIG-IP Next CNF (1.1.0–1.4.3, 2.0.0–2.2.3, 2.3.0–2.3.2). The vulnerability was published on July 15, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, F5 Advisory).

技術的な詳細

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), where the BIG-IP HTTP/2 processing code fails to impose adequate restrictions on memory allocation when handling certain undisclosed request patterns. An unauthenticated, remote attacker can send specially crafted HTTP/2 requests to a virtual server with an HTTP/2 profile enabled, causing the TMM process to progressively consume memory without releasing it. This is a data plane issue only — the control plane is not exposed, meaning administrative interfaces are not directly at risk. No authentication or user interaction is required, and the attack can be automated, making it particularly accessible to threat actors (GitHub Advisory, F5 Advisory).

影響

Successful exploitation causes progressive memory exhaustion in the TMM process, leading to degraded system performance and ultimately a denial-of-service condition on the BIG-IP system. The impact is limited to availability — there is no confidentiality or integrity impact, and no lateral movement or data exfiltration risk is associated with this vulnerability. Service disruption persists until the TMM process is forcibly or manually restarted, potentially causing extended outages for traffic passing through affected virtual servers (GitHub Advisory, F5 Advisory).

エクスプロイト可能性

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at the time of publication. The EPSS score is approximately 0.33–0.46%, indicating a low near-term exploitation probability. The attack is classified as automatable (no user interaction required), which lowers the barrier for opportunistic exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the available data (GitHub Advisory, F5 Advisory).

エクスプロイテーションのステップ

  1. Reconnaissance: Identify internet-facing F5 BIG-IP systems using tools such as Shodan or Censys, filtering for systems presenting HTTP/2 on virtual server endpoints. Confirm the target is running an affected version (e.g., BIG-IP 17.1.x before 17.1.3.4, 17.5.x before 17.5.1.8, 21.0.x before 21.0.0.3, or 21.1.x before 21.1.0.1).
  2. Confirm HTTP/2 profile: Attempt an HTTP/2 connection to the target virtual server to verify that an HTTP/2 profile is active (e.g., using curl --http2 or nghttp).
  3. Send crafted HTTP/2 requests: Transmit undisclosed request patterns (specific request structure not publicly known) over HTTP/2 to the target virtual server. The requests trigger abnormal memory allocation within the TMM process without proper release.
  4. Sustain the attack: Continuously send requests to maintain memory pressure, causing progressive memory exhaustion and system performance degradation.
  5. Achieve DoS: The TMM process becomes resource-starved, causing service disruption for all traffic handled by the affected virtual server until an administrator manually restarts the TMM process (GitHub Advisory, F5 Advisory).

妥協の兆候

  • Network: Sustained or high-volume HTTP/2 traffic directed at BIG-IP virtual server endpoints from unexpected or unknown source IPs; unusual HTTP/2 connection patterns (e.g., high request rates without corresponding legitimate application traffic).
  • System Performance: Steadily increasing memory utilization on the TMM process observable via BIG-IP management dashboards or tmsh show sys performance commands; system alerts or SNMP traps related to memory thresholds being exceeded.
  • Logs: BIG-IP system logs (/var/log/ltm) showing TMM memory warnings or OOM-related messages; logs indicating TMM process restarts or crashes correlated with inbound HTTP/2 traffic spikes.
  • Process: TMM process exhibiting abnormally high and growing memory consumption without a corresponding increase in legitimate traffic load; repeated unplanned TMM restarts.

軽減策と回避策

F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1; BIG-IP Next for Kubernetes 2.2.3 and 2.3.2; BIG-IP Next SPK 1.7.18; and BIG-IP Next CNF 1.4.3, 2.2.3, and 2.3.2. As a workaround prior to patching, administrators should consider removing or restricting HTTP/2 profiles from virtual servers where not strictly required, implementing network-level rate limiting or request filtering for HTTP/2 connections, and monitoring TMM memory utilization closely. Upgrading to a patched version is the recommended long-term remediation (F5 Advisory, GitHub Advisory).

コミュニティの反応

The vulnerability received coverage from multiple cybersecurity news outlets including CyberSecurityNews and SecurityOnline, with articles highlighting the memory exhaustion risk to BIG-IP deployments (CyberSecurityNews). Field Effect and The Hacker News included it in weekly security roundups, indicating moderate industry attention (Field Effect Blog, The Hacker News). A Reddit thread in r/sysadmin discussed the vulnerability, reflecting practitioner-level awareness among BIG-IP administrators. CISA included it in its weekly vulnerability bulletin (SB26-201), signaling relevance to government and critical infrastructure operators (CISA Bulletin).

関連情報


ソース: このレポートは AI を使用して生成されました

関連 F5 BIG-IP Virtual Edition (tier - best) 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-94127CRITICAL9.3
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
はいはいSep 22, 2026
CVE-2026-66842HIGH8.7
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-iq_centralized_management
いいえはいSep 02, 2026
CVE-2026-59762HIGH8.7
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいJul 15, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいMay 13, 2026
CVE-2026-63020LOW2.3
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいSep 02, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者