CVE-2026-22548: BIG-IP Advanced WAF and ASM vulnerability
Published Feb 4, 2026
·Updated
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate.
Affected Software
6 affected componentsFixes available
F5 Networks BIG-IP Advanced WAF
F5 Networks BIG-IP ASM
F5 BIG-IP Advanced WAF/ASM
F5 BIG-IP Advanced WAF/ASM>=17.1.0<=17.1.2
17.1.3
F5 Big-ip Advanced Web Application Firewall>=17.1.0<17.1.3
F5 BIG-IP Application Security Manager>=17.1.0<17.1.3
Event History
Feb 4, 2026
Advisory Published
via F5·02:28 PM
Data Sourced
via F5·02:28 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-22548?
CVE-2026-22548 has a high severity rating due to its ability to cause the bd process to terminate under specific conditions.
2
How do I fix CVE-2026-22548?
To fix CVE-2026-22548, upgrade your F5 BIG-IP Advanced WAF or ASM to version 17.1.3 or later.
3
Which products are affected by CVE-2026-22548?
CVE-2026-22548 affects F5 Networks BIG-IP Advanced WAF and BIG-IP ASM when configured on a virtual server.
4
What are the implications of not addressing CVE-2026-22548?
If not addressed, CVE-2026-22548 can lead to service interruptions due to the termination of the bd process.
5
Is there a workaround for CVE-2026-22548?
Currently, there is no official workaround for CVE-2026-22548 apart from applying the recommended update.