CVE-2026-2507

7.5

F5 · BIG-IP

A NULL pointer dereference vulnerability in F5 BIG-IP allows unauthenticated remote attackers to cause a denial of service by sending specifically crafted traffic.

Executive summary

A critical denial of service vulnerability in F5 BIG-IP allows unauthenticated attackers to terminate the Traffic Management Microkernel (TMM) process remotely.

Vulnerability

The vulnerability, classified as a NULL pointer dereference (CWE-476), occurs when BIG-IP AFM or BIG-IP DDoS modules are provisioned. An unauthenticated attacker can send undisclosed traffic patterns that trigger a process crash, resulting in a system-wide denial of service.

Business impact

The exploitation of this vulnerability results in the termination of the TMM process, which effectively halts all traffic processing for the affected BIG-IP device. Given the critical role of BIG-IP as a load balancer and security gateway, this disruption causes significant service downtime, potentially impacting all downstream applications and services. With a CVSS score of 7.5, the risk is classified as High due to the ease of exploitation and the severe impact on availability.

Remediation

Immediate Action: Update F5 BIG-IP installations to the fixed versions, which include 21.0.0, 17.1.0, 16.1.0, or later, as specified in the vendor advisory.

Proactive Monitoring: Monitor system logs for repeated TMM service restarts or unexpected process termination events that correlate with spikes in incoming traffic.

Compensating Controls: Deploy WAF rules or ACLs to filter suspicious or malformed traffic patterns until the software can be patched, though patching remains the only definitive resolution.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a significant risk to network availability and must be treated with urgency. Administrators should prioritize patching the affected F5 BIG-IP systems to the recommended versions to prevent potential service disruption caused by unauthenticated remote actors.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.