F5 has confirmed a flaw in BIG-IP DNS that lets a remote attacker knock the system offline, and there is no patch for it. The vendor is offering workarounds instead, each of which means switching off a feature.
The issue is tracked as CVE-2026-11622. F5 lists BIG-IP DNS versions 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0 as affected. Hong Kong's HKCERT, which relayed the advisory to its constituents on 21 September, rated the bulletin high risk specifically because no fix is available yet.
A crash here takes more than one box down
BIG-IP DNS is not a web server. It is the appliance that answers DNS queries for a large network and steers traffic between sites, so it sits in front of whatever an organization actually runs. When it stops answering, the services behind it become unreachable even though those services are perfectly healthy. That is what makes an availability bug in this particular product worth a maintenance window rather than a backlog ticket.
What F5 has not said
F5's advisory describes the impact as denial of service and stops there. The bulletin carries no CVSS score, it does not describe how the flaw is triggered, and neither F5 nor HKCERT reports any exploitation in the wild. IntelFusions will not fill those gaps. The affected component and the shape of the workarounds are suggestive, but guessing at a mechanism the vendor has not described would be speculation rather than reporting. Administrators who need the detail should read F5's own advisory, which is the original source here; HKCERT's restatement is published here.
Disable DNSSEC validation, or change the cache type
With no patch to apply, F5 offers three workarounds, and an administrator needs only one of them:
- Disable DNSSEC in a validating resolver DNS cache.
- Switch the cache to a Resolver or Transparent type.
- Disable the Use BIND Server on BIG-IP option on the DNS profile.
Each one removes a capability, so none of them is free. Turning off DNSSEC validation gives up the cryptographic checking that stops a resolver accepting forged answers, which is a genuine trade and deserves a deliberate decision rather than a reflex. Teams that cannot accept that trade are left waiting for F5 to ship a fix.
The second one on this product since August
This is the second unpatched denial of service issue in BIG-IP DNS that IntelFusions has covered since early August, after a separate flaw in the same product line that also arrived with workarounds and no fix. It lands in the same week that ISC patched fourteen flaws in BIND, several of which could equally knock DNS offline. BIG-IP remains a target in its own right, too: researchers recently pulled a memory-only web shell out of compromised BIG-IP APM appliances.
DNS infrastructure rarely makes headlines until it stops working, and then it makes all of them. An unpatched availability bug in the appliance that answers for an entire estate is worth the downtime it takes to apply a workaround, even when every option on the table means giving something up.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.