Unchecked Return Value in BIG-IP - CVE-2026-40060
Published: May 14, 2026
BIG-IP
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to unchecked return value in the bd process when handling undisclosed requests on a virtual server with a BIG-IP Advanced WAF or ASM security policy configured. A remote attacker can send crafted requests to cause a denial of service.
This is a data plane issue only and there is no control plane exposure.