Monday , September 14 2026
HTTP/2

F5 Fixes HTTP/2 Vuln Enabling Massive DoS Attacks

F5 Networks has revealed a new HTTP/2 vulnerability impacting several BIG-IP products, which could enable remote attackers to conduct denial-of-service attacks on corporate networks.

The security flaw named CVE-2025-54500, known as the “HTTP/2 MadeYouReset Attack,” was announced on August 13, 2025, with updates on August 15.

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

The vulnerability exploits malformed HTTP/2 control frames to overwhelm systems and has been assigned a medium severity rating with CVSS scores of 5.3 (v3.1) and 6.9 (v4.0).

HTTP/2 Protocol Exploit Uncovered:

Security researchers have identified that attackers can manipulate malformed HTTP/2 control frames to break the maximum concurrent streams limit, effectively bypassing built-in protocol safeguards.

The attack method allows remote, unauthenticated attackers to cause substantial increases in CPU usage, potentially leading to complete denial of service on affected BIG-IP systems.

Key characteristics of this vulnerability include:

Attack Type: HTTP/2 MadeYouReset Attack using malformed control frames.
Authentication Required: None – remote, unauthenticated exploitation possible.
Primary Impact: CPU resource exhaustion leading to denial of service.
Classification: CWE-770 (Allocation of Resources Without Limits or Throttling).
Exposure Level: Data plane only, no control plane compromise.
F5 Internal IDs: 1937817 (BIG-IP), 1937817-5 (BIG-IP Next), 1937817-6 (Next SPK/CNF/K8s).

F5 Products Widely Affected:

The vulnerability affects an extensive range of F5 products, with BIG-IP systems bearing the brunt of the impact. Vulnerable versions include BIG-IP 17.x (versions 17.5.0-17.5.1 and 17.1.0-17.1.2), BIG-IP 16.x (versions 16.1.0-16.1.6), and BIG-IP 15.x (versions 15.1.0-15.1.10).

F5 has released engineering hotfixes for the 17.x and 16.x branches, specifically Hotfix-BIGIP-17.5.1.0.80.7-ENG.iso and Hotfix-BIGIP-17.1.2.2.0.259.12-ENG.iso for the 17.x series, and Hotfix-BIGIP-16.1.6.0.27.3-ENG.iso for the 16.x series.

BIG-IP Next products are also affected, including versions 20.3.0 and various SPK, CNF, and Kubernetes implementations.

However, several F5 products remain unaffected, including BIG-IQ Centralized Management, F5 Distributed Cloud services, NGINX products, F5OS systems, and F5 AI Gateway. F5 Silverline services are vulnerable only when HTTP/2 enabled proxy configurations are in use.

F5 strongly recommends immediate implementation of available hotfixes for affected systems, while acknowledging that engineering hotfixes do not undergo the extensive quality assurance testing of regular releases.

For organizations unable to immediately apply patches, F5 suggests several mitigation strategies. The primary recommendation is disabling HTTP/2 and reverting to HTTP where configurations allow this change.

Check Also

ShinyHunters

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center …