High severity7.5NVD Advisory· Published Jul 15, 2026· Updated Aug 6, 2026
CVE-2026-59762
CVE-2026-59762
Description
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.
Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
1Patches
Vulnerability mechanics
References
1- my.f5.com/manage/s/article/K000162231nvdVendor Advisory
News mentions
2- Weekly Cyber Security Newsletter Bulletin – Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 StoriesCyber Security News · Jul 26, 2026
- New HTTP/2 Vulnerability Lets Hackers Crash Servers With Memory Exhaustion AttacksCyber Security News · Jul 24, 2026