CVE-2026-40061Disclosure(f5 / big-ip_domain_name_system)

LOWCVSS 8.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • big-ip_domain_name_system

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
big-ip_domain_name_system

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-17: 1PoC Mentioned / Linked · 2026-05-17: 1Technical Details · 2026-05-17: 105-17
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Israel@f1tym1
    Disclosure

    CVE-2026-40061 | F5 BIG-IP prior 17.1.3.1/17.5.1.4/21.0.0.1 iControl REST command injection (K000160788 / WID-SEC-2026-1532) https://ift.tt/a6pvqZg A vulnerability was found in F5 BIG-IP. It has been classified as critical. The impacted element is an unknown function of the co…

    Post summary

    The text announces a critical iControl REST command injection vulnerability (CVE-2026-40061) in specific F5 BIG‑IP firmware versions, providing a link for more details but no evidence of exploitation or mitigation.

    0001052
    974 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appf5big-ip_domain_name_system---
Appf5big-ip_domain_name_system21.0.0--

Explore more