← Back to Feed

F5 Products Denial of Service Vulnerability

CVE-2026-42534

August 11, 2026 · HKCERT · Severity: HIGH

This advisory describes a denial-of-service vulnerability in multiple F5 products, including BIG-IP Next and BIG-IP DNS. No patch exists, so F5 provides workarounds such as restricting upstream DNS servers and enabling DNS-over-TLS. Organizations should review the vendor advisory and apply mitigations.

Key Takeaways

  • No patch available for CVE-2026-42534; administrators should apply vendor workarounds immediately.
  • Affected F5 products include BIG-IP Next SPK, CNF, Kubernetes, and DNS versions listed.
  • Restrict upstream DNS servers, use DNS-over-TLS, segment networks, and disable unneeded DNS features.
☕ Buy a Coffee