CVE-2026-59762
F5 BIG-IP Virtual Edition (tier - best) vulnerability analysis and mitigation

Overview

CVE-2026-59762 is a denial-of-service vulnerability in F5 BIG-IP and BIG-IP Next products caused by uncontrolled memory resource consumption when an HTTP/2 profile is configured on a virtual server. Undisclosed requests trigger excessive memory utilization in the Traffic Management Microkernel (TMM) process, degrading system performance until TMM is restarted. Affected products include BIG-IP (versions 17.1.0–17.1.3.4, 17.5.0–17.5.1.8, 21.0.0–21.0.0.3, 21.1.0–21.1.0.1), BIG-IP Next for Kubernetes (2.0.0–2.2.3, 2.3.0–2.3.2), BIG-IP Next SPK (1.7.0–1.7.18, 1.9.0+), and BIG-IP Next CNF (1.1.0–1.4.3, 2.0.0–2.2.3, 2.3.0–2.3.2). The vulnerability was published on July 15, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, F5 Advisory).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), where the BIG-IP HTTP/2 processing code fails to impose adequate restrictions on memory allocation when handling certain undisclosed request patterns. An unauthenticated, remote attacker can send specially crafted HTTP/2 requests to a virtual server with an HTTP/2 profile enabled, causing the TMM process to progressively consume memory without releasing it. This is a data plane issue only — the control plane is not exposed, meaning administrative interfaces are not directly at risk. No authentication or user interaction is required, and the attack can be automated, making it particularly accessible to threat actors (GitHub Advisory, F5 Advisory).

Impact

Successful exploitation causes progressive memory exhaustion in the TMM process, leading to degraded system performance and ultimately a denial-of-service condition on the BIG-IP system. The impact is limited to availability — there is no confidentiality or integrity impact, and no lateral movement or data exfiltration risk is associated with this vulnerability. Service disruption persists until the TMM process is forcibly or manually restarted, potentially causing extended outages for traffic passing through affected virtual servers (GitHub Advisory, F5 Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at the time of publication. The EPSS score is approximately 0.33–0.46%, indicating a low near-term exploitation probability. The attack is classified as automatable (no user interaction required), which lowers the barrier for opportunistic exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the available data (GitHub Advisory, F5 Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing F5 BIG-IP systems using tools such as Shodan or Censys, filtering for systems presenting HTTP/2 on virtual server endpoints. Confirm the target is running an affected version (e.g., BIG-IP 17.1.x before 17.1.3.4, 17.5.x before 17.5.1.8, 21.0.x before 21.0.0.3, or 21.1.x before 21.1.0.1).
  2. Confirm HTTP/2 profile: Attempt an HTTP/2 connection to the target virtual server to verify that an HTTP/2 profile is active (e.g., using curl --http2 or nghttp).
  3. Send crafted HTTP/2 requests: Transmit undisclosed request patterns (specific request structure not publicly known) over HTTP/2 to the target virtual server. The requests trigger abnormal memory allocation within the TMM process without proper release.
  4. Sustain the attack: Continuously send requests to maintain memory pressure, causing progressive memory exhaustion and system performance degradation.
  5. Achieve DoS: The TMM process becomes resource-starved, causing service disruption for all traffic handled by the affected virtual server until an administrator manually restarts the TMM process (GitHub Advisory, F5 Advisory).

Indicators of compromise

  • Network: Sustained or high-volume HTTP/2 traffic directed at BIG-IP virtual server endpoints from unexpected or unknown source IPs; unusual HTTP/2 connection patterns (e.g., high request rates without corresponding legitimate application traffic).
  • System Performance: Steadily increasing memory utilization on the TMM process observable via BIG-IP management dashboards or tmsh show sys performance commands; system alerts or SNMP traps related to memory thresholds being exceeded.
  • Logs: BIG-IP system logs (/var/log/ltm) showing TMM memory warnings or OOM-related messages; logs indicating TMM process restarts or crashes correlated with inbound HTTP/2 traffic spikes.
  • Process: TMM process exhibiting abnormally high and growing memory consumption without a corresponding increase in legitimate traffic load; repeated unplanned TMM restarts.

Mitigation and workarounds

F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1; BIG-IP Next for Kubernetes 2.2.3 and 2.3.2; BIG-IP Next SPK 1.7.18; and BIG-IP Next CNF 1.4.3, 2.2.3, and 2.3.2. As a workaround prior to patching, administrators should consider removing or restricting HTTP/2 profiles from virtual servers where not strictly required, implementing network-level rate limiting or request filtering for HTTP/2 connections, and monitoring TMM memory utilization closely. Upgrading to a patched version is the recommended long-term remediation (F5 Advisory, GitHub Advisory).

Community reactions

The vulnerability received coverage from multiple cybersecurity news outlets including CyberSecurityNews and SecurityOnline, with articles highlighting the memory exhaustion risk to BIG-IP deployments (CyberSecurityNews). Field Effect and The Hacker News included it in weekly security roundups, indicating moderate industry attention (Field Effect Blog, The Hacker News). A Reddit thread in r/sysadmin discussed the vulnerability, reflecting practitioner-level awareness among BIG-IP administrators. CISA included it in its weekly vulnerability bulletin (SB26-201), signaling relevance to government and critical infrastructure operators (CISA Bulletin).

Additional resources


SourceThis report was generated using AI

Related F5 BIG-IP Virtual Edition (tier - best) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-66842HIGH8.7
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesSep 02, 2026
CVE-2026-59762HIGH8.7
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesJul 15, 2026
CVE-2026-42930HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_application_security_manager
NoYesMay 13, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_application_security_manager
NoYesMay 13, 2026
CVE-2026-63020LOW2.3
  • F5 BIG-IP Virtual Edition (tier - best) logoF5 BIG-IP Virtual Edition (tier - best)
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management