PatchSiren cyber security CVE debrief
CVE-2026-34019 F5 CVE debrief
CVE-2026-34019 is a medium-severity vulnerability affecting F5 BIG-IP products. When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets. This can lead to the configured routing protocol failing over. The vulnerability has a CVSS score of 6.3 and is considered medium severity. Software versions that have reached End of Technical Support (EoTS) are not evaluated.
- Vendor
- F5
- Product
- BIG-IP
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-13
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-05-13
- Advisory updated
- 2026-06-29
Who should care
Organizations using F5 BIG-IP products with BFD configured in Static and Dynamic routing protocols should be aware of this vulnerability. Specifically, those using versions 17.1.0-17.1.2 and 17.5.0 are affected. Additionally, users of versions 16.1.0-16.1.6 are also vulnerable. F5 has provided a vendor advisory for mitigation.
Technical summary
The vulnerability exists in the Traffic Management Microkernel (TMM) when processing BFD packets. Undisclosed traffic can cause the TMM to stop processing BFD packets, leading to a failover of the configured routing protocol. The affected products include BIG-IP Access Policy Manager, BIG-IP Advanced Firewall Manager, BIG-IP Advanced Web Application Firewall, and others. The CVSS vector for this vulnerability is CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.
Defensive priority
This vulnerability requires immediate attention. Affected organizations should review their BIG-IP configurations and apply the necessary mitigations or patches as recommended by F5.
Recommended defensive actions
- Review BIG-IP configurations for BFD in Static and Dynamic routing protocols.
- Apply vendor-recommended mitigations or patches.
- Monitor Traffic Management Microkernel (TMM) performance.
- Consider compensating controls for routing protocol security.
- Inventory affected BIG-IP products and prioritize patching.
Evidence notes
The CVE record and NVD detail provide comprehensive information about the vulnerability. F5 has released a vendor advisory (K000150508) for mitigation. The vulnerability affects multiple BIG-IP products across various versions.
Official resources
-
CVE-2026-34019 CVE record
CVE.org
-
CVE-2026-34019 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
This article is AI-assisted and based on the supplied source corpus.