CVE-2026-40618
published 2026-05-13CVE-2026-40618: When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.32%
24.5th percentile
When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
99 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | — | — |
| f5 | big-ip | >= 16.1.0 < * | * |
| f5 | big-ip | >= 17.1.0 < 17.1.3.1 | 17.1.3.1 |
| f5 | big-ip | >= 17.5.0 < 17.1.5.4 | 17.1.5.4 |
| f5 | big-ip | >= 21.0.0 < 21.0.0.1 | 21.0.0.1 |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_access_policy_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_access_policy_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_advanced_firewall_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_advanced_firewall_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_advanced_web_application_firewall | — | — |
| f5 | big-ip_advanced_web_application_firewall | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_advanced_web_application_firewall | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_advanced_web_application_firewall | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_analytics | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_analytics | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 16.1.0 – 16.1.6 | — |
| f5 | big-ip_application_acceleration_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_application_acceleration_manager | 17.5.0 – 17.5.1 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2026-40618: When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Techno...
vendor_f5·2026-05-13·CVSS 8.7
CVE-2026-40618 [HIGH] CWE-131 CVE-2026-40618: When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Techno...
CVE-2026-40618: When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Techno...
When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: BIG-IP
F5 Advisory Articles: K000158082
F5 References: https://my.f5.com/manage/s/article/K000158082
VulDB
F5 BIG-IP prior 17.1.3.1/17.1.5.4/21.0.0.1 Traffic Management Microkernel buffer size (K000158082 / Nessus ID 316090)
vuldb·2026-05-25·CVSS 8.7
CVE-2026-40618 [HIGH] F5 BIG-IP prior 17.1.3.1/17.1.5.4/21.0.0.1 Traffic Management Microkernel buffer size (K000158082 / Nessus ID 316090)
A vulnerability was found in F5 BIG-IP, BIG-IP Next SPK, BIG-IP Next CNF and BIG-IP Next for Kubernetes. It has been rated as critical. This impacts an unknown function of the component Traffic Management Microkernel. This manipulation causes incorrect calculation of buffer size.
The identification of this vulnerability is CVE-2026-40618. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-jrwx-v3xx-xrp8: When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware
ghsa_unreviewed·2026-05-13
CVE-2026-40618 [HIGH] CWE-131 GHSA-jrwx-v3xx-xrp8: When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware
When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-13
Published