CVE-2026-42781
published 2026-05-13CVE-2026-42781: When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic…
PriorityP426medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.18%
7.5th percentile
When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
66 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 17.1.0 < 17.1.3.1 | 17.1.3.1 |
| f5 | big-ip | >= 17.5.0 < 17.5.1.4 | 17.5.1.4 |
| f5 | big-ip | >= 21.0.0 < 21.0.0.1 | 21.0.0.1 |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_access_policy_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_advanced_firewall_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_advanced_web_application_firewall | — | — |
| f5 | big-ip_advanced_web_application_firewall | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_advanced_web_application_firewall | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_analytics | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_application_acceleration_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_application_security_manager | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_application_visibility_and_reporting | — | — |
| f5 | big-ip_application_visibility_and_reporting | 17.1.0 – 17.1.3 | — |
| f5 | big-ip_application_visibility_and_reporting | 17.5.0 – 17.5.1 | — |
| f5 | big-ip_automation_toolchain | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.07.1HIGHCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2026-42781: When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can ...
vendor_f5·2026-05-13·CVSS 7.1
CVE-2026-42781 [HIGH] CWE-835 CVE-2026-42781: When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can ...
CVE-2026-42781: When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can ...
When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5 Advisory Articles: K000160862
F5 References: https://my.f5.com/manage/s/article/K000160862
VulDB
F5 BIG-IP prior 17.1.3.1/17.5.1.4/21.0.0.1 Traffic Management Microkernel infinite loop (K000160862 / Nessus ID 316097)
vuldb·2026-05-24·CVSS 7.1
CVE-2026-42781 [HIGH] F5 BIG-IP prior 17.1.3.1/17.5.1.4/21.0.0.1 Traffic Management Microkernel infinite loop (K000160862 / Nessus ID 316097)
A vulnerability was found in F5 BIG-IP. It has been declared as problematic. The affected element is an unknown function of the component Traffic Management Microkernel. The manipulation results in infinite loop.
This vulnerability is known as CVE-2026-42781. Access to the local network is required for this attack. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
GHSA-543h-qfcx-5xww: When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Tra
ghsa_unreviewed·2026-05-13
CVE-2026-42781 [HIGH] CWE-835 GHSA-543h-qfcx-5xww: When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Tra
When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-13
Published