CVE-2026-22548
Unknown Unknown - Not Provided

Denial of Service via bd Process Crash in BIG-IP WAF/ASM

Vulnerability report for CVE-2026-22548, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-02-04

Last updated on: 2026-02-13

Assigner: F5 Networks

Description

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-02-04
Last Modified
2026-02-13
Generated
2026-07-26
AI Q&A
2026-02-04
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
f5 big-ip_advanced_web_application_firewall From 17.1.0 (inc) to 17.1.3 (exc)
f5 big-ip_application_security_manager From 17.1.0 (inc) to 17.1.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-362 The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability occurs when a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server. Under certain undisclosed request conditions, which are beyond the attacker's control, the bd process can terminate unexpectedly.

Detection Guidance

I don't know

Impact Analysis

The vulnerability can cause the bd process to terminate, which may lead to denial of service or disruption of the security functions provided by the BIG-IP Advanced WAF or ASM, potentially impacting the availability of the protected services.

Compliance Impact

I don't know

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-22548. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart