CVE-2026-41227: BIG-IP HTTP/2 Layer 7 Dos Protection vulnerability
On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41227?
CVE-2026-41227 has a high severity rating of 8.7.
How do I fix CVE-2026-41227?
To address CVE-2026-41227, ensure your F5 BIG-IP software is updated to a version that mitigates this vulnerability.
What systems are affected by CVE-2026-41227?
CVE-2026-41227 affects F5 Big-IP Advanced Web Application Firewall, F5 BIG-IP Application Security Manager, and F5 Big-ip DDoS Hybrid Defender.
What impact does CVE-2026-41227 have on my system?
CVE-2026-41227 can lead to increased memory consumption, potentially causing the Traffic Management Microkernel (TMM) process to terminate.
Is there a workaround for CVE-2026-41227?
Currently, the recommended approach for CVE-2026-41227 is to patch or upgrade your vulnerable F5 BIG-IP systems.