Denial of Service Vulnerability in BIG-IP Advanced WAF by F5 Networks
CVE-2026-40060
8.7HIGH
What is CVE-2026-40060?
A specific configuration of security policies on F5 Networks' BIG-IP Advanced Web Application Firewall (WAF) or Application Security Manager (ASM) can lead to unexpected terminations of the bd process due to undisclosed request patterns. This vulnerability poses potential risks for stability and availability, impacting web application performance and security posture.
Affected Version(s)
BIG-IP 21.0.0 < 21.0.0.1
BIG-IP 17.5.0 < 17.5.1.4
BIG-IP 17.1.0 < 17.1.3.1