PatchSiren cyber security CVE debrief
CVE-2026-40618 F5 CVE debrief
A high-severity vulnerability was discovered in BIG-IP, a product by F5 Networks. The vulnerability, tracked as CVE-2026-40618, can cause the Traffic Management Microkernel (TMM) to terminate when an SSL profile is configured on a virtual server without Intel QuickAssist Technology (QAT) or when the database variable crypto.hwacceleration is set to disabled. This can lead to a denial of service, making the affected systems unavailable. The vulnerability has a CVSS score of 8.7 and is considered high severity.
- Vendor
- F5
- Product
- BIG-IP
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-13
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-05-13
- Advisory updated
- 2026-06-29
Who should care
Administrators and security teams responsible for managing BIG-IP systems should be aware of this vulnerability and take immediate action to mitigate the risk. This includes reviewing system configurations, updating to patched versions, and implementing compensating controls if necessary.
Technical summary
The vulnerability exists in BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled. When an SSL profile is configured on a virtual server, undisclosed traffic can cause the TMM to terminate, resulting in a denial of service. The vulnerability affects multiple versions of BIG-IP, including 16.1.0-16.1.6, 17.1.0-17.1.3, and 17.5.0-17.5.1.
Defensive priority
This vulnerability has a high CVSS score of 8.7 and can cause significant disruption to BIG-IP systems. Immediate attention is required to mitigate the risk, especially for which the affected systems are critical or have high traffic volumes.
Recommended defensive actions
- Review BIG-IP system configurations to ensure Intel QuickAssist Technology (QAT) is utilized if available.
- Update BIG-IP systems to patched versions (17.1.4 or later, 17.5.2 or later, 16.1.7 or later).
- Implement compensating controls, such as rate limiting or traffic filtering, to reduce exposure.
- Monitor system logs and traffic patterns for signs of exploitation attempts.
- Perform regular vulnerability assessments and penetration testing to identify potential weaknesses.
Evidence notes
The CVE-2026-40618 vulnerability was identified through analysis of BIG-IP system configurations and traffic patterns. The CVSS score of 8.7 indicates high severity, and the potential impact on BIG-IP systems is significant. F5 has provided mitigation guidance and patches for affected versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-40618 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-40618
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-40618 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40618
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://my.f5.com/manage/s/article/K000158082
[email protected] - Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.