SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-26457

HIGH · CVSS 7.5 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

F5 products utilizing the ccoap library version 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 are vulnerable to a null pointer dereference in the coap_dump_msg() function, triggered by COAP messages with zero-length options. This vulnerability could lead to application crashes or denial of service, making it critical for organizations using affected F5 products to prioritize remediation efforts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-26457
Severity
HIGH
CVSS
7.5
EPSS
0.34%
F5

Original NVD Description

ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_dump_msg() function when processing COAP messages containing options with zero length.