2026-013: Critical Vulnerability in F5 BIG-IP APM
Cybersecurity Classified by Officially
On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild [1].
CERT-EU recommends taking appropriate actions as soon as possible.
The vulnerability CVE-2026-94127, with a CVSS score of 9.8, is a heap-based buffer overflow vulnerability and allow unauthenticated attacker to achieve remote code execution (RCE) on the affected device [1].
The vulnerability affects the following versions of BIG-IP APM if configured with an access policy and an OAuth profile on a virtual server [1]:
CERT-EU recommends taking the following actions as soon as possible:
If patching cannot be applied immediately, F5 provides an iRule-based mitigation for the affected virtual server. To obtain it, F5 BIG-IP clients should contact the F5 support [1].
CERT-EU strongly advises to look for the following indicators of compromise provided by the vendor in its advisory [1]:
At a high level, multiple OAuth authentication failures, followed by suspicious commands, shortly followed by a TMM SIGABRT is the combination that should lead to human review of the system.
/var/log/apm for repeated occurrences of the following, especially 10 or more from a single IP in a short window.<DATE> <HOST> err tmm1\[30975\]: 01990004:3: <PROFILE\_NAME>: Request UserInfo from Source ID (null) IP <IP> failed. Error Code (invalid\_token) Error Description (The access token is invalid.) total_failed:$ tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed Audit log anomalies: if OAuth failures are observed, review /var/log/audit around those timestamps for suspicious commands.
This is an extract. The publication continues at the source.
Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-013/
Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- CERT-EU — imported from official source
- Official source
- https://www.cert.europa.eu/publications/security-advisories-rss RSS
- Imported
- September 22, 2026 17:30
- Versions
- 1 recorded
- Identity
security-advisories-10950