CVE-2026-22548
F5 BIG-IP Virtual Edition (tier - best) vulnerability analysis and mitigation

Overview

CVE-2026-22548 is a denial-of-service vulnerability affecting F5 BIG-IP Advanced Web Application Firewall (Advanced WAF) and BIG-IP Application Security Manager (ASM). When a security policy is configured on a virtual server, specially crafted undisclosed requests — combined with conditions beyond the attacker's control — can cause the bd (BIG-IP daemon) process to terminate, resulting in service disruption. Affected versions are 17.1.0 through 17.1.2; version 17.1.3 and later contain the fix. Software versions that have reached End of Technical Support (EoTS) are not evaluated. The vulnerability carries a CVSS v3.1 base score of 5.9 (Medium) and a CVSS v4.0 base score of 8.2 (High) (F5 Advisory).

Technical details

The root cause is classified as CWE-362 — Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition). The vulnerability arises when the bd process, responsible for enforcing Advanced WAF or ASM security policies on a virtual server, encounters specific undisclosed request patterns under race-condition-like circumstances that trigger an unhandled termination. Exploitation requires no authentication or user interaction, but does depend on conditions outside the attacker's direct control (e.g., timing or internal system state), which limits reliable triggering. No public technical write-up or proof-of-concept code has been disclosed (F5 Advisory, Feedly).

Impact

Successful exploitation causes the bd process to crash, disabling the Advanced WAF or ASM security policy enforcement on the affected virtual server. This results in a denial-of-service condition where legitimate traffic may be disrupted or security inspection may be bypassed, depending on the system's failsafe configuration. There is no impact on confidentiality or integrity — the vulnerability is limited to availability (F5 Advisory).

Indicators of compromise

  • Logs: Unexpected termination or restart entries for the bd process in BIG-IP system logs (/var/log/ltm or /var/log/bd); repeated bd process crash events correlated with inbound traffic spikes.
  • Process: Absence of the bd process when it should be running; automatic restarts of bd triggered by the BIG-IP watchdog.
  • Network: Unusual or malformed HTTP/HTTPS requests to virtual servers protected by Advanced WAF or ASM policies, particularly those with anomalous headers or payloads that do not match expected application traffic patterns.

Mitigation and workarounds

F5 has released BIG-IP version 17.1.3 as the fix for this vulnerability; organizations running versions 17.1.0 through 17.1.2 should upgrade immediately. Systems on End of Technical Support (EoTS) versions should be evaluated separately for upgrade feasibility. As interim measures, network segmentation and access controls that limit exposure of BIG-IP virtual server interfaces to trusted sources can reduce the attack surface while patching is planned (F5 Advisory).

Community reactions

The vulnerability was covered alongside other F5 BIG-IP and NGINX patches released in February 2026, with security news outlets including CyberSecurityNews, GBHackers, Heise, and The Hacker News reporting on the broader F5 patch release (CyberSecurityNews, GBHackers, Heise). A Reddit thread in r/pwnhub discussed the Cisco and F5 patch releases together, reflecting moderate community interest (Reddit). No significant independent researcher commentary or vendor statements beyond the official F5 advisory have been identified.

Additional resources


SourceThis report was generated using AI

Related F5 BIG-IP Virtual Edition (tier - best) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59762HIGH8.7
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesJul 15, 2026
CVE-2026-42920HIGH8.7
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42930HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42924HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_domain_name_system
NoYesMay 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management