CVE-2026-59762: F5 BIG-IP Next Cloud-Native Network Functions
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
- F5 BIG-IP Next Cloud-Native Network Functions: from 1.1.0, before 1.4.3 (fixed in 1.4.3); from 2.0.0, before 2.2.3 (fixed in 2.2.3); version 2.3.0 only
- F5 BIG-IP Next For Kubernetes: from 2.0.0, before 2.2.3 (fixed in 2.2.3); version 2.3.0 only
- F5 BIG-IP Next Service Proxy For Kubernetes: from 1.7.0, before 1.7.18 (fixed in 1.7.18); from 1.8.0, up to and including 1.9.2; from 2.0.0, up to and including 2.0.3
Published 2026-07-15. Last modified 2026-08-06.