PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40703 F5 CVE debrief

A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility. This vulnerability, tracked as CVE-2026-40703, has a CVSS score of 5.3 and is considered medium severity. The vulnerability affects various versions of BIG-IP products, including BIG-IP Access Policy Manager, BIG-IP Advanced Firewall Manager, and others. Software versions that have reached End of Technical Support (EoTS) are not evaluated. F5 has provided mitigation guidance for this issue.

Vendor
F5
Product
BIG-IP
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-13
Original CVE updated
2026-06-24
Advisory published
2026-05-13
Advisory updated
2026-06-24

Who should care

Organizations using affected BIG-IP products should prioritize patching or applying mitigations. Specifically, administrators of BIG-IP Configuration utility should be aware of the potential for CSRF attacks and take steps to protect their systems. Security teams should review their inventory of BIG-IP products and ensure that necessary patches or workarounds are applied.

Technical summary

CVE-2026-40703 is a CSRF vulnerability in the BIG-IP Configuration utility. An attacker could exploit this vulnerability by tricking an authenticated user into performing unintended actions on the BIG-IP system. The vulnerability is caused by inadequate protection against CSRF attacks in the BIG-IP Configuration utility. Affected products include BIG-IP Access Policy Manager, BIG-IP Advanced Firewall Manager, BIG-IP Advanced Web Application Firewall, and others. The CVSS vector for this vulnerability is CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.

Defensive priority

Apply patches or mitigations provided by F5 as soon as possible. Review BIG-IP product inventory and ensure necessary patches or workarounds are applied.

Recommended defensive actions

  • Apply patches or mitigations provided by F5.
  • Review BIG-IP product inventory and ensure necessary patches or workarounds are applied.
  • Monitor BIG-IP systems for suspicious activity.
  • Implement additional security controls, such as web application firewalls, to detect and prevent CSRF attacks.
  • Educate administrators on the risks of CSRF attacks and the importance of patching and mitigation.

Evidence notes

The CVE record and NVD detail provide information on the vulnerability and its impact. F5 has provided mitigation guidance for this issue. The vulnerability affects various versions of BIG-IP products.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-40703 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-40703

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-40703 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40703

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.