CVE-2026-22548Patch(f5 / big-ip_advanced_web_application_firewall)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch f5 big-ip_advanced_web_application_firewall systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • big-ip_advanced_web_application_firewall
  • big-ip_application_security_manager

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-05); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
big-ip_advanced_web_application_firewallbig-ip_application_security_manager

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-02-04: 1Mentions · 2026-02-05: 2Mentions · 2026-02-06: 2Mentions · 2026-02-09: 1Mentions · 2026-02-13: 1Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-02-06: 2Patch / Workaround · 2026-02-13: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-05: 2Technical Details · 2026-02-06: 2Technical Details · 2026-02-13: 102-0402-0502-0602-0902-13
Signal classification2 categories
Patch
457.1%
Disclosure
342.9%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-041
Disclosure1
2026-02-052
Disclosure1Patch1
2026-02-062
Patch2
2026-02-091
Disclosure1
2026-02-131
Patch1
Full discourse7 posts
  • iototsecnews@iototsecnews
    Patch

    F5 の脆弱性 CVE-2026-22548/22549/1642 などが FIX:BIG-IP や NGINX などに影響 https://iototsecnews.jp/2026/02/06/f5-patches-critical-vulnerabilities-in-big-ip-nginx-and-related-products/ F5 製品群 (BIG-IP/NGINX/CIS など) のソフトウェアにおける一連の問題の原因は、大量の通信や特殊な形式のリクエストを、適切に処理できないという不備にあります。具体的には、NGINX や WAF 製品が、悪意を持って細工された通信データを受け取った際に、システムの処理能力を使い果たしたサービスが、停止してしまうという問題が見つかりました。これにより、本来は正常な通信をさばくはずのロード・バランサーやファイアウォールが反応しなくなり、Web サイトやアプリにアクセスできなくなる、サービス拒否 (DoS) 状態に陥るリスクが生じています。ご利用のチームは、ご注意ください。 #BIGIP #CVE20261642 #CVE202620730 #CVE202620732 #CVE202622548 #CVE202622549 #F5 #nginx #Vulnerability

    Post summary

    The post announces critical CVEs (CVE-2026-22548/22549/1642) affecting F5 BIG‑IP, NGINX, and related products, details a DoS vulnerability caused by malformed requests, and indicates that patches are available.

    02010160
    483 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos F5 ❗ CVE-2026-22548 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-f5-2/ https://t.co/hx9dG4Hs4h

    Post summary

    A new vulnerability in F5 products, CVE-2026-22548, is announced with a link to additional information.

    00011211
    6.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    ⚠️⚠️⚠️ BIG-IP Advanced WAF/ASMでデータプレーンからの認証不要のDoS K000158072: BIG-IP Advanced WAF and ASM vulnerability CVE-2026-22548 https://my.f5.com/manage/s/article/K000158072

    Post summary

    An F5 BIG‑IP Advanced WAF/ASM vulnerability (CVE‑2026‑22548) permits unauthenticated denial‑of‑service from the data plane.

    01010627
    6.7K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 F5 Urges Rapid Patching After High-Severity BIG-IP & NGINX Flaws Hit CVSS 8.2 F5’s Feb 6, 2026 Quarterly Security Notification fixes high-severity issues in BIG-IP Advanced WAF/ASM (CVE-2026-22548) and multiple NGINX products (CVE-2026-1642) that could enable security control bypass, privilege escalation, or service manipulation—plus a BIG-IP CIS issue (CVE-2026-22549) impacting Kubernetes/OpenShift ingress. Organizations running affected BIG-IP/NGINX stacks should urgently inventory, patch to fixed releases (e.g., BIG-IP 17.1.3; CIS 2.20.2), and apply SMTP module hardening to reduce exposure. 🎯 Target: Global/Enterprise (BIG-IP, NGINX, Kubernetes/OpenShift deployments) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/f5-patches-critical-vulnerabilities/

    Post summary

    F5 issues a security advisory for three high‑severity CVEs, urging immediate patching and hardening of BIG‑IP, NGINX, and Kubernetes/OpenShift deployments.

    0000089
    191 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 F5 February 2026 Security Bulletin: BIG-IP & NGINX Fixes for DoS and Config Exposures F5’s February 2026 Quarterly Security Notification patches multiple BIG-IP/NGINX issues, including medium-severity DoS risks (e.g., BIG-IP Advanced WAF/ASM CVE-2026-22548, NGINX CVE-2026-1642, BIG-IP CIS CVE-2026-22549) plus lower-severity bugs like local privilege escalation in BIG-IP Config Utility (CVE-2026-20732) and an SMTP configuration exposure—making upgrades urgent for internet-facing WAF/Ingress deployments. 🎯 Target: Global/Enterprise & Internet-Facing WAF/Ingress #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/f5-patches-critical-vulnerabilities/

    Post summary

    The bulletin announces patches for several F5 BIG-IP and NGINX vulnerabilities, urging immediate upgrades to mitigate DoS, privilege escalation, and configuration exposure risks.

    0000067
    191 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Cisco & F5 patch high-severity bugs: unauth TelePresence DoS + Cisco Meeting Management root RCE Cisco fixed CVE-2026-20119 (unauthenticated remote DoS via crafted meeting invite) and CVE-2026-20098 (authenticated arbitrary file upload leading to root command execution in Cisco Meeting Management), while F5’s Feb 2026 advisories include high-rated BIG-IP/NGINX issues such as CVE-2026-22548 that can restart critical processes and disrupt traffic. 🎯 Target: Global/Enterprise (Cisco Collaboration + F5 BIG-IP/NGINX) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/cisco-f5-patch-high-severity-vulnerabilities/

    Post summary

    Cisco and F5 released patches for high‑severity CVEs, including CVE‑2026‑20119, CVE‑2026‑20098, and CVE‑2026‑22548, addressing DoS and root RCE vulnerabilities.

    0000052
    192 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22548 F5 BIG-IP Advanced WAF Process Termination Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22548

    Post summary

    A new vulnerability, CVE-2026-22548, is disclosed for F5 BIG‑IP Advanced WAF that can terminate processes, but no PoC, exploit, or mitigation details are provided.

    0000063
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appf5big-ip_advanced_web_application_firewall---
Appf5big-ip_application_security_manager---

Explore more