F5 informerar om kritisk sårbarhet i BIG-IP APM

Imported from official source

Announcement

Cybersecurity Classified by Officially

F5 har publicerat information om en kritisk sårbarhet, CVE-2026-94127, i BIG-IP APM. Sårbarheten kan resultera i att en oautentiserad angripare kan fjärrexekvera godtycklig kod.

Sårbarheten utnyttjas aktivt och har fått en CVSS-klassning på 9.8. [1]

Påverkade produkter

Sårbarheten påverkar följande versioner av BIG-IP APM:

  • 21.1.0
  • 17.5.0 till 17.5.1
  • 17.1.0 till 17.1.3

Produkten är endast sårbar ifall denna är konfigurerad med en access policy samt en OAuth profil på en virtuell server. Den sårbara komponenten är APM OAuth, läs mer på leverantörens webbplats. [1]

Rekommendationer

CERT-SE rekommenderar att omgående applicera leverantörens säkerhetsuppdatering. CERT-SE uppmanar även organisationer att uppdatera utanför den ordinarie patch-cykeln, om möjligt.

CERT-SE uppmanar att söka efter avvikande beteenden i produkten enligt leverantörens anvisningar. [1]

Källor

This is an extract. The publication continues at the source.

Source: CERT-SE.

Read the original at the source: https://www.cert.se/2026/09/information-om-kritisk-sarbarhet-i-big-ip-apm.html

Officially imported this from CERT-SE’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
CERT-SE — imported from official source
Official source
https://www.cert.se/feed/atom.xml ATOM
Imported
October 03, 2026 20:38
Versions
1 recorded
Identity
https://www.cert.se/2026/09/information-om-kritisk-sarbarhet-i-big-ip-apm.html

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.