Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN919
_____________________________________________________________________

DATE                : 23/09/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):  Systems running F5 BIG-IP APM software.
  
=====================================================================
https://my.f5.com/manage/s/article/K000162605?mkt_tok=NjUzLVNNQy03ODMAAAGkaH9ofwJ_SRrYgVTlugDrbGmtsu1nH57-t7CLkyTTdZHlyphUFNtULl3ACEteoRszBciQ_4gjkNsWTnQqQfftwYMNCzWPXxGhUqTJ-emmdyUmrf_dqfI
https://cert.europa.eu/publications/security-advisories/2026-013
_____________________________________________________________________

 K000162605: BIG-IP APM vulnerability CVE-2026-94127
Published Date: Sep 22, 2026Updated Date: Sep 23, 2026

    Download Article

AI Recommended Content

Security Advisory Description

When a BIG-IP APM access policy and an OAuth profile are configured on
a virtual server, specific malicious traffic can lead to remote code
execution (RCE). This vulnerability is only present when BIG-IP APM
is configured as an OAuth Authorization Server. Deployments using APM
strictly as an OAuth Client / Resource Server (without OAuth
authorization server profiles configured) are not affected by this
vulnerability. (CVE-2026-94127)

Important: We have learned that this vulnerability has been exploited.

Impact

This vulnerability allows an unauthenticated attacker to perform RCE.
The BIG-IP system in Appliance mode is also vulnerable. This is a data
plane issue; there is no control plane exposure.


Security Advisory Status

F5 Product Development has assigned ID 2524777 (BIG-IP) to this
vulnerability. This issue has been classified as CWE-122 Heap-based
Buffer Overflow.

To determine if your product and version have been evaluated for this
vulnerability, refer to the Evaluated products box. To determine if
your release is known to be vulnerable, the components or features
that are affected by the vulnerability, and for information about
releases, point releases, or hotfixes that address the vulnerability,
refer to the following tables. You can also use iHealth to diagnose a
vulnerability for BIG-IP, BIG-IQ, and F5OS systems. For more
information about using iHealth, refer to K27404821: Using F5 iHealth
to diagnose vulnerabilities. For more information about security
advisory versioning, refer to K51812227: Understanding security
advisory versioning.


In this section

    BIG-IP Next
    BIG-IP and BIG-IQ
    F5 Distributed Cloud and NGINX Services
    F5OS
    NGINX
    Other products


BIG-IP Next
Product	Branch   Versions known to be vulnerable1   Fixes introduced in
Severity/CVSS score    Vulnerable component or feature

BIG-IP Next CNF   All   None   Not applicable   Not vulnerable   None
BIG-IP Next for Kubernetes   All   None   Not applicable   Not vulnerable   None

1F5 evaluates only software versions that have not yet reached the
End of Technical Support (EoTS) phase of their lifecycle. For more
information, refer to the Security hotfixes section of K4602:
Overview of the F5 security vulnerability response policy.


BIG-IP and BIG-IQ

Note: After F5 releases a fix for a given branch, that fix applies
to all subsequent minor, maintenance, and point releases for that
branch; F5 will not list additional fixes for that branch in the
table. For example, when F5 releases a fix in 17.1.2.1, the fix
also applies to 17.1.2.2 and all later 17.1.x releases
(17.1.3.x, 17.1.4.x). For more information, refer to K51812227:
Understanding security advisory versioning.


Product	Branch	Versions known to be vulnerable1
Fixes introduced in   Severity/CVSS score2   Vulnerable component or feature

BIG-IP APM   21.x   21.1.0   Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso3
             17.x	17.5.0 - 17.5.1
             17.1.0 - 17.1.3	Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso3
                                Hotfix-BIGIP 17.1.3.5.0.41.14-ENG.iso3
             Critical/9.8 (CVSS v3.1)
             Critical/9.3 (CVSS v4.0)	APM OAuth

BIG-IP (all other modules)	All	None	Not applicable
Not vulnerable	None

BIG-IQ Centralized Management	All	None	Not applicable
Not vulnerable	None

1F5 evaluates only software versions that have not yet reached the
End of Technical Support (EoTS) phase of their lifecycle. For
more information, refer to the Security hotfixes section of
K4602: Overview of the F5 security vulnerability response policy.

2Starting with the August 2024 Quarterly Security Notification,
F5 will provide the CVSS v4.0 base score in addition to the CVSS
v3.1 score, for first-party security issues only. The CVSS score
link takes you to a resource outside of MyF5, and the content may
be removed without our knowledge. For more information about how
F5 uses CVSS v4.0, refer to K000140363: Overview of CVSS v4.0 in
F5 security advisories.

3F5 has fixed this issue in an engineering hotfix that is
available on F5 Downloads. The EHFs contain all fixes in BIG-IP
Hardened Releases 2 (HR2) and K000163302: Overview of
engineering hotfix (EHF) release on BIG-IP version 17.5.1.9
and 17.1.3.5.


F5 Distributed Cloud and NGINX Services

Service    Severity/CVSS score   Vulnerable component or feature

F5 Distributed Cloud (all services)   Not vulnerable   None
NGINX One Console   Not vulnerable   None


F5OS

Product	Branch    Versions known to be vulnerable1 
Fixes introduced in   Severity/CVSS score   Vulnerable component or feature

F5OS	All	None	Not applicable	Not vulnerable	None
F5OS-A	All	None	Not applicable	Not vulnerable	None
F5OS-C	All	None	Not applicable	Not vulnerable	None

1F5 evaluates only software versions that have not yet reached
the End of Technical Support (EoTS) phase of their lifecycle.
For more information, refer to the Security hotfixes section
of K4602: Overview of the F5 security vulnerability response
policy.


NGINX

Product	Branch   Versions known to be vulnerable1  
Fixes introduced in   Severity/CVSS score   Vulnerable component or feature

NGINX (all products)   All   None   Not applicable   Not vulnerable   None

1F5 evaluates only software versions that have not yet reached
the End of Technical Support (EoTS) phase of their lifecycle. For
more information, refer to the Security hotfixes section of K4602:
Overview of the F5 security vulnerability response policy.


Other products

Product	Branch   Versions known to be vulnerable1
Fixes introduced in   Severity/CVSS score   Vulnerable component or feature

F5 AI Gateway   All   None   Not applicable   Not vulnerable   None

1F5 evaluates only software versions that have not yet reached
the End of Technical Support (EoTS) phase of their lifecycle.
For more information, refer to the Security hotfixes section
of K4602: Overview of the F5 security vulnerability response
policy.


Security Advisory Recommended Actions

If you are running a version listed in the Versions known to be
vulnerable column, you can eliminate this vulnerability by
installing a version listed in the Fixes introduced in column.
If the Fixes introduced in column does not list a version for
your branch, then no update candidate currently exists for that
branch and F5 recommends that you upgrade to a version with the
fix (refer to the tables).

If the Fixes introduced in column lists a version prior to the
one you are running, in the same branch, then your version
should have the fix.


Mitigation

To mitigate this vulnerability, you can apply an iRule to the
affected BIG-IP APM virtual server. Contact F5 Support to
obtain the iRule.


Indicators of Compromise for ID 2524777

Three indicators observed close in time to one another should be
considered a reason to investigate further. Presence of these
indicators alone does not necessarily mean there is an issue,
but combination and frequency have been seen to correlate with
an attack.

At a high level, multiple OAuth authentication failures, followed
by suspicious commands, shortly followed by a TMM SIGABRT is the
combination that should lead to human review of the system.


OAuth failures

This is a medium confidence indicator of attack. The log message
is normal to observe in some situations, so the signal here is
repetition not presence. Sustained repetition (>= 10 in one log)
is the anomaly a human should review, especially if all observed
from a single IP address. While the log message presence alone
does not confirm compromise, it should be considered as potential
indicator of attack.


Log messages

/var/log/apm

<DATE> <HOST> err tmm1[30975]: 01990004:3: <PROFILE_NAME>: Request UserInfo from Source ID (null) IP <IP> failed. Error Code (invalid_token) Error Description (The access token is invalid.)


TMCTL statistics

The following command will output the statistics for BIG-IP APM OAuth
failures. An unexplained increase in total_failed should be
investigated further.

$ tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed

Audit log entries

/var/log/audit

If the log oauth failures messages above are noticed, especially in
rapid succession or large volume, the time stamps should be noted,
and audit logs should be investigated around those time stamps.


TMM core file presence

We have observed TMM enters a loop, which causes the SOD daemon to
send a SIGABRT. Presence of a TMM core file alone is not an indicator,
but core files should be investigated.


Acknowledgments

This issue was discovered internally by F5.


Related Content

    K41942608: Overview of MyF5 security advisory articles
    K12201527: Overview of F5 security notifications
    K51812227: Understanding security advisory versioning
    K4602: Overview of the F5 security vulnerability
response policy
    K4918: Overview of the F5 critical issue hotfix policy
    K39757430: F5 product and services lifecycle policy index
    K9502: BIG-IP hotfix and point release matrix
    K13123: Managing BIG-IP product hotfixes (15.x - 21.x)
    K000090258: Download F5 products from MyF5
    K9970: Subscribe to email notifications regarding F5
products and security announcements
    K9957: Creating a custom RSS feed to view new and
updated documents
    K44525501: Overview of BIG-IP data plane and
control plane
    K000135931: Contact F5 Support


AI Recommended Content

    Security Advisory - K000162605: BIG-IP APM
vulnerability CVE-2026-94127
    Security Advisory - K000162604: NGINX ngx_http_v3_module
vulnerability CVE-2026-90439
    Knowledge - K000135931: Contact F5 Support
    Security Advisory - K000163347: GnuTLS vulnerability
CVE-2026-33845
_____________________________________________________________________

Security Advisory 2026-013

    Security Advisories

Release Date:
22-09-2026 16:52:36

Critical Vulnerability in F5 BIG-IP APM


History:

    22/09/2026 --- v1.0 -- Initial publication

Summary

On 22 September 2026, F5 published an advisory addressing a critical
vulnerability affecting its BIG-IP APM product. The vendor confirmed
active exploitation in the wild [1].

CERT-EU recommends taking appropriate actions as soon as possible.


Technical Details

The vulnerability CVE-2026-94127, with a CVSS score of 9.8, is a
heap-based buffer overflow vulnerability and allow unauthenticated
attacker to achieve remote code execution (RCE) on the affected
device [1].


Affected Products

The vulnerability affects the following versions of BIG-IP APM if
configured with an access policy and an OAuth profile on a virtual
server [1]:

    17.1.0 - 17.1.3
    17.5.0 - 17.5.1
    21.1.0

Recommendations

CERT-EU recommends taking the following actions as soon as possible:

    Preserve forensic evidence.
    Apply the relevant hotfix.
    Check for signs of compromise (see the compromise assessment section).
If any sign of compromise is detected, start the incident response process.

Mitigation

If patching cannot be applied immediately, F5 provides an iRule-based
mitigation for the affected virtual server. To obtain it, F5 BIG-IP
clients should contact the F5 support [1].


Compromise Assessment

CERT-EU strongly advises to look for the following indicators of
compromise provided by the vendor in its advisory [1]:

At a high level, multiple OAuth authentication failures, followed by
suspicious commands, shortly followed by a TMM SIGABRT is the
combination that should lead to human review of the system.

    OAuth authentication failures: check /var/log/apm for repeated
occurrences of the following, especially 10 or more from a single
IP in a short window.

<DATE> <HOST> err tmm1\[30975\]: 01990004:3: <PROFILE\_NAME>: Request UserInfo from Source ID (null) IP <IP> failed. Error Code (invalid\_token) Error Description (The access token is
invalid.) 

    Increase of OAuth failure statistics. Run the following and
look for an unexplained increase in total_failed:

$ tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed 

    Audit log anomalies: if OAuth failures are observed, review
/var/log/audit around those timestamps for suspicious commands.

    TMM core files: Presence of a TMM core file alone is not an
indicator, but core files should be investigated. The vendor
indicates that they have observed TMM entering a loop, which
causes the SOD daemon to send a SIGABRT.


References

[1] https://my.f5.com/manage/s/article/K000162605?mkt_tok=NjUzLVNNQy03ODMAAAGkaH9ofwJ_SRrYgVTlugDrbGmtsu1nH57-t7CLkyTTdZHlyphUFNtULl3ACEteoRszBciQ_4gjkNsWTnQqQfftwYMNCzWPXxGhUqTJ-emmdyUmrf_dqfI


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




