このページはまだあなたの言語に翻訳されていません。翻訳作業中のため、英語でコンテンツを表示しています。

💡 Keep dependencies up to date — most exploits target known, patchable vulnerabilities.

HIGHCVE-2026-41956CVSS 7.5

CVE-2026-41956: DoS in F5 BIG-IP via UDP Classification

プラットフォーム

linux

コンポーネント

bigip

修正版

17.5.1.4

あなたの言語に翻訳中…

CVE-2026-41956 describes a denial-of-service (DoS) vulnerability in F5 BIG-IP. When a classification profile is configured on a UDP virtual server, specially crafted requests can trigger a crash in the Traffic Management Microkernel (TMM), leading to service disruption. This vulnerability impacts versions 16.1.0 through 17.5.1.4, and a fix is available in version 17.5.1.4.

影響と攻撃シナリオ翻訳中…

Successful exploitation of CVE-2026-41956 allows an attacker to induce a denial-of-service condition on the affected F5 BIG-IP system. This results in the Traffic Management Microkernel (TMM) terminating, effectively halting traffic processing and rendering the virtual server unavailable. The impact can range from temporary service outages to prolonged disruptions, potentially affecting critical applications and services dependent on the BIG-IP infrastructure. The blast radius is limited to the specific UDP virtual server and its associated services, but widespread impact is possible if the affected BIG-IP device handles high-volume traffic or is a critical component of the network infrastructure. While no public exploits are currently available, the DoS nature of the vulnerability makes it a potential target for opportunistic attacks.

悪用の状況翻訳中…

CVE-2026-41956 was published on May 13, 2026. The vulnerability is not currently listed on CISA KEV or EPSS, suggesting a low to medium probability of exploitation. No public proof-of-concept (POC) code is currently available. Given the DoS nature of the vulnerability and the potential for easy exploitation via crafted requests, it is recommended to prioritize remediation.

脅威インテリジェンス

エクスプロイト状況

概念実証不明
CISA KEVNO
インターネット露出

CISA SSVC

悪用状況none
自動化可能yes
技術的影響partial

CVSS ベクトル

脅威インテリジェンス· CVSS 3.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H7.5HIGHAttack VectorNetwork攻撃者がターゲットに到達する方法Attack ComplexityLow悪用に必要な条件Privileges RequiredNone攻撃に必要な認証レベルUser InteractionNone被害者の操作が必要かどうかScopeUnchanged影響コンポーネント外への波及ConfidentialityNone機密データ漏洩のリスクIntegrityNone不正データ改ざんのリスクAvailabilityHighサービス障害のリスクnextguardhq.com · CVSS v3.1 基本スコア
これらのメトリクスの意味は?
Attack Vector
ネットワーク — インターネット経由でリモートから悪用可能。物理・ローカルアクセス不要。
Attack Complexity
低 — 特別な条件不要。安定して悪用可能。
Privileges Required
なし — 認証不要。資格情報なしで悪用可能。
User Interaction
なし — 自動かつ無音の攻撃。被害者は何もしない。
Scope
変化なし — 影響は脆弱なコンポーネントのみ。
Confidentiality
なし — 機密性への影響なし。
Integrity
なし — 完全性への影響なし。
Availability
高 — 完全なクラッシュまたはリソース枯渇。完全なサービス拒否。

影響を受けるソフトウェア

コンポーネントbigip
ベンダーF5
最小バージョン16.1.0
最大バージョン17.5.1.4
修正版17.5.1.4

弱点分類 (CWE)

タイムライン

  1. 予約済み
  2. 公開日

緩和策と回避策翻訳中…

The primary mitigation for CVE-2026-41956 is to upgrade F5 BIG-IP to version 17.5.1.4 or later, which contains the fix. If immediate upgrade is not feasible, consider implementing temporary workarounds. Review and restrict access to UDP virtual servers with classification profiles, limiting exposure to untrusted sources. Implement rate limiting on UDP traffic to mitigate the impact of potential DoS attacks. Monitor BIG-IP system logs for unusual traffic patterns or error messages related to TMM crashes. After upgrading, confirm the fix by sending a test request to the affected UDP virtual server and verifying that TMM remains stable.

修正方法翻訳中…

Actualice su sistema BIG-IP a una versión que incluya la corrección para evitar la terminación inesperada de TMM. Consulte la nota de seguridad de F5 (https://my.f5.com/manage/s/article/K000158038) para obtener más detalles y las versiones específicas afectadas y corregidas.

よくある質問翻訳中…

What is CVE-2026-41956 — DoS in F5 BIG-IP?

CVE-2026-41956 is a denial-of-service vulnerability affecting F5 BIG-IP versions 16.1.0 through 17.5.1.4. Malicious requests can crash the Traffic Management Microkernel (TMM), causing service disruption.

Am I affected by CVE-2026-41956 in F5 BIG-IP?

You are affected if you are running F5 BIG-IP versions 16.1.0 through 17.5.1.4 and have UDP virtual servers configured with classification profiles.

How do I fix CVE-2026-41956 in F5 BIG-IP?

Upgrade to F5 BIG-IP version 17.5.1.4 or later to resolve the vulnerability. Consider temporary workarounds like rate limiting if immediate upgrade is not possible.

Is CVE-2026-41956 being actively exploited?

There are currently no reports of active exploitation, but the DoS nature of the vulnerability makes it a potential target.

Where can I find the official F5 advisory for CVE-2026-41956?

Refer to the official F5 security advisory for CVE-2026-41956 on the F5 website (https://www.f5.com/security/center/alerts).

あなたのプロジェクトは影響を受けていますか?

依存関係ファイルをアップロードすれば、このCVEや他のCVEがあなたに影響するか即座にわかります。

scanZone.liveBadgescanZone.eyebrow

今すぐ試す — アカウント不要

Upload any manifest (composer.lock, package-lock.json, WordPress plugin list…) or paste your component list. You get a vulnerability report instantly. Uploading a file is just the start: with an account you get continuous monitoring, Slack/email alerts, multi-project and white-label reports.

手動スキャンSlack/メールアラートContinuous monitoringホワイトラベルレポート

依存関係ファイルをドラッグ&ドロップ

composer.lock、package-lock.json、requirements.txt、Gemfile.lock、pubspec.lock、Dockerfile...