CVE-2026-34019: F5 BIG-IP Access Policy Manager

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets and cause the configured routing protocol to fail over.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

  • F5 BIG-IP Access Policy Manager: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Advanced Firewall Manager: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Advanced Web Application Firewall: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Analytics: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Application Acceleration Manager: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Application Security Manager: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Application Visibility And Reporting: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Automation Toolchain: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Carrier-Grade Nat: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Container Ingress Services: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Ddos Hybrid Defender: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Domain Name System: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Edge Gateway: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Fraud Protection Service: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Global Traffic Manager: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Link Controller: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Local Traffic Manager: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Policy Enforcement Manager: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP SSL Orchestrator: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Webaccelerator: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6
  • F5 BIG-IP Websafe: from 17.1.0, up to and including 17.1.2; version 17.5.0 only; from 16.1.0, up to and including 16.1.6

Published 2026-05-13. Last modified 2026-06-29.