SB2026051440 - Remote denial of service in BIG-IP Advanced WAF and ASM
Published: May 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Unchecked Return Value (CVE-ID: CVE-2026-40060)
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to unchecked return value in the bd process when handling undisclosed requests on a virtual server with a BIG-IP Advanced WAF or ASM security policy configured. A remote attacker can send crafted requests to cause a denial of service.
This is a data plane issue only and there is no control plane exposure.
Remediation
Install update from vendor's website.