CVE-2026-40435CWE-420

BIG-IP httpd access control vulnerability

Medium · published May 13, 2026

CVSS v4.0
6.9
EPSS
0%
Percentile
13.5
In the wild
Unconfirmed
What it is

When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The record
Technical detail
CVSS v4.0
6.9 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00228 · 13.5th percentile
Weakness
CWE-420 · Unprotected Alternate Channel
Published
2026-05-13T14:12Z
EPSS history
Timeline
  • 13 MAY 14:12Z
    BIG-IP httpd access control vulnerability
    cvelistv5