CVE-2026-40060: BIG-IP Advanced WAF and ASM vulnerability
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40060?
CVE-2026-40060 has a high severity score of 8.7.
How do I fix CVE-2026-40060?
To mitigate CVE-2026-40060, ensure you are using a software version of F5 BIG-IP that is still in technical support and apply the necessary patches or updates provided by F5.
What does CVE-2026-40060 affect?
CVE-2026-40060 affects the F5 BIG-IP Application Security Manager and F5 BIG-IP Advanced Web Application Firewall when specific security policies are configured.
What are the risks associated with CVE-2026-40060?
The primary risk associated with CVE-2026-40060 is the potential termination of the bd process, leading to disruptions in security services.
Is the software version relevant for CVE-2026-40060?
Yes, only software versions that are still within their technical support phase are evaluated for CVE-2026-40060.