
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42920 is a Denial of Service vulnerability in F5 BIG-IP affecting the Traffic Management Microkernel (TMM). When a Client SSL profile is configured with "Allow Dynamic Record Sizing" on a UDP virtual server, undisclosed traffic can cause the TMM process to terminate. The vulnerability was published on May 13, 2026, and affects BIG-IP versions 17.1.0 < 17.1.3.1, 17.5.0 < 17.5.1.4, 21.0.0 < 21.0.0.1, and 16.1.x (all versions); software versions that have reached End of Technical Support (EoTS) are not evaluated. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, F5 Advisory).
The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop), indicating that specially crafted network traffic triggers an unrecoverable loop condition within the TMM process, ultimately causing it to terminate. The attack vector is network-based, requiring no authentication, no user interaction, and no special privileges — only that the target BIG-IP device has a Client SSL profile with "Allow Dynamic Record Sizing" enabled on a UDP virtual server. The specific traffic pattern that triggers the condition has not been publicly disclosed by F5. No public proof-of-concept exploit code is known to exist at this time (GitHub Advisory, F5 Advisory).
Successful exploitation causes the TMM — the core data-plane process responsible for handling all traffic on F5 BIG-IP appliances — to terminate, resulting in a complete loss of availability for all services managed by the affected BIG-IP instance. There is no confidentiality or integrity impact; the attack is purely a Denial of Service. Depending on the deployment context, a TMM crash could disrupt load balancing, application delivery, and SSL/TLS termination for all downstream applications, potentially affecting large numbers of end users and critical business services (GitHub Advisory, F5 Advisory).
/var/log/tmm or /var/log/ltm; repeated TMM restart messages in BIG-IP system logs; core dump files generated in /var/core/ following TMM crashes.tmm process or rapid TMM restarts observable via tmsh show sys tmm-info or system monitoring dashboards.F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.1, 17.5.1.4, and 21.0.0.1. Organizations unable to upgrade immediately should disable "Allow Dynamic Record Sizing" on Client SSL profiles associated with UDP virtual servers if this feature is not operationally required. Additionally, implementing network-based access controls to restrict which sources can send traffic to affected UDP virtual servers can reduce exposure. Upgrading to a patched version is the recommended long-term remediation (F5 Advisory, GitHub Advisory).
Coverage of CVE-2026-42920 has been limited to automated vulnerability tracking platforms and security aggregators such as VulDB, CVEFeed, and Eclypsium's May 2026 hardware fix summary. No notable independent researcher commentary or significant social media discussion has been identified. The vulnerability was detected by Tenable's Nessus scanner (plugin 316096), indicating it has been incorporated into standard vulnerability management tooling (Tenable Plugin, Eclypsium Summary).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."