2026-013: Critical Vulnerability in F5 BIG-IP APM

Imported from official source

Advisory

Cybersecurity Classified by Officially

  • 22/09/2026 --- v1.0 -- Initial publication
  • On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild [1].

    CERT-EU recommends taking appropriate actions as soon as possible.

    The vulnerability CVE-2026-94127, with a CVSS score of 9.8, is a heap-based buffer overflow vulnerability and allow unauthenticated attacker to achieve remote code execution (RCE) on the affected device [1].

    The vulnerability affects the following versions of BIG-IP APM if configured with an access policy and an OAuth profile on a virtual server [1]:

    CERT-EU recommends taking the following actions as soon as possible:

  • Check for signs of compromise (see the compromise assessment section). If any sign of compromise is detected, start the incident response process.
  • If patching cannot be applied immediately, F5 provides an iRule-based mitigation for the affected virtual server. To obtain it, F5 BIG-IP clients should contact the F5 support [1].

    CERT-EU strongly advises to look for the following indicators of compromise provided by the vendor in its advisory [1]:

    At a high level, multiple OAuth authentication failures, followed by suspicious commands, shortly followed by a TMM SIGABRT is the combination that should lead to human review of the system.

  • OAuth authentication failures: check /var/log/apm for repeated occurrences of the following, especially 10 or more from a single IP in a short window.
  • <DATE> <HOST> err tmm1\[30975\]: 01990004:3: <PROFILE\_NAME>: Request UserInfo from Source ID (null) IP <IP> failed. Error Code (invalid\_token) Error Description (The access token is invalid.) 
  • Increase of OAuth failure statistics. Run the following and look for an unexplained increase in total_failed:
  • $ tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed 

    Audit log anomalies: if OAuth failures are observed, review /var/log/audit around those timestamps for suspicious commands.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-013/

    Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    CERT-EU — imported from official source
    Official source
    https://www.cert.europa.eu/publications/security-advisories-rss RSS
    Imported
    September 22, 2026 17:30
    Versions
    1 recorded
    Identity
    security-advisories-10950

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.