National cyber authorities in Belgium and Canada warned about CVE-2026-2507, a high-severity denial-of-service (DoS) vulnerability in F5 BIG-IP Traffic Management Microkernel (TMM) affecting BIG-IP AFM and BIG-IP DDoS Hybrid Defender when those modules are provisioned. The issue impacts versions 17.x through 17.5.1.4 and can be triggered remotely over the network by an unauthenticated attacker using undisclosed traffic that can cause TMM to terminate, resulting in service interruption and loss of availability (CVSS 7.5).
Both advisories direct organizations to F5’s vendor bulletin K000160003 and recommend applying the relevant updates with high priority. The Centre for Cybersecurity Belgium additionally advises increasing monitoring/detection for suspicious activity and notes that patching prevents future exploitation but does not remediate any potential prior compromise, and provides incident reporting guidance via its national CERT channel.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-19, Belgium's Centre for Cybersecurity issued a warning that the F5 BIG-IP TMM vulnerability could lead to denial of service and urged immediate patching. This was a government advisory amplifying F5's disclosure rather than a separate vulnerability event.
On 2026-02-18, F5 published security advisory AV26-144 for a BIG-IP TMM vulnerability tracked as CVE-2026-2507 affecting certain BIG-IP products, including BIG-IP AFM and DDoS Hybrid Defender in the 17.x train. The advisory referenced version 17.5.1.4 and directed customers to apply the available updates to remediate the issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.