CVE-2026-59762
F5 BIG-IP Virtual Edition (tier - best) vulnerability analysis and mitigation

Overview

CVE-2026-59762 is a denial-of-service vulnerability in F5 BIG-IP and BIG-IP Next products caused by uncontrolled memory resource consumption when an HTTP/2 profile is configured on a virtual server. Undisclosed requests trigger excessive memory utilization in the Traffic Management Microkernel (TMM) process, degrading system performance until TMM is restarted. Affected products include BIG-IP (versions 17.1.0–17.1.3.4, 17.5.0–17.5.1.8, 21.0.0–21.0.0.3, 21.1.0–21.1.0.1), BIG-IP Next for Kubernetes (2.0.0–2.2.3, 2.3.0–2.3.2), BIG-IP Next SPK (1.7.0–1.7.18, 1.9.0+), and BIG-IP Next CNF (1.1.0–1.4.3, 2.0.0–2.2.3, 2.3.0–2.3.2). The vulnerability was published on July 15, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, F5 Advisory).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), where the BIG-IP TMM process fails to impose adequate restrictions on memory allocation when processing certain HTTP/2 requests. An unauthenticated remote attacker can send specially crafted HTTP/2 requests to a virtual server with an HTTP/2 profile enabled, causing progressive memory exhaustion. The vulnerability is a data plane issue only — there is no control plane exposure, meaning management interfaces are not directly affected. No public proof-of-concept code has been identified at this time (GitHub Advisory, F5 Advisory).

Impact

Successful exploitation causes progressive memory resource exhaustion in the TMM process, leading to degraded system performance and ultimately a denial-of-service condition on the BIG-IP system. The impact is limited to availability — there is no confidentiality or integrity impact, and no lateral movement or data exposure risk is associated with this vulnerability. Service disruption persists until the TMM process is either forced to restart automatically or manually restarted by an administrator, potentially causing significant downtime for traffic managed by the affected virtual servers (GitHub Advisory, F5 Advisory).

Indicators of compromise

  • Network: Unusual volume of HTTP/2 requests to virtual servers with HTTP/2 profiles enabled; connections from unexpected or anonymous source IPs targeting BIG-IP data plane interfaces.
  • System Performance: Sustained or progressive increase in TMM process memory utilization observable via BIG-IP monitoring dashboards or tmsh show sys performance commands.
  • Logs: BIG-IP system logs (/var/log/ltm) showing TMM memory warnings, OOM (out-of-memory) events, or unexpected TMM process restarts.
  • Process: TMM process restart events or watchdog-triggered restarts logged in /var/log/tmm or /var/log/daemon.log.

Mitigation and workarounds

F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1; BIG-IP Next for Kubernetes 2.2.3 and 2.3.2; BIG-IP Next SPK 1.7.18; and BIG-IP Next CNF 1.4.3, 2.2.3, and 2.3.2. As interim mitigations, administrators should configure network-level rate limiting or request filtering for HTTP/2 connections, monitor TMM memory utilization closely, and consider restricting HTTP/2 profile usage to only necessary virtual servers. Upgrading to a patched version is the recommended long-term remediation (F5 Advisory, GitHub Advisory).

Community reactions

The vulnerability received community attention on Reddit's r/sysadmin shortly after disclosure, with administrators discussing impact assessment and patching timelines. Field Effect published a blog post covering F5 updates including this CVE, and The Hacker News included it in a weekly security recap. CISA referenced the vulnerability in its security bulletin SB26-201. No significant researcher controversy or vendor dispute has been noted (Field Effect Blog, The Hacker News, CISA Bulletin).

Additional resources


SourceThis report was generated using AI

Related F5 BIG-IP Virtual Edition (tier - best) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59762HIGH8.7
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesJul 15, 2026
CVE-2026-42920HIGH8.7
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42930HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42924HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesMay 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management