JPCERT-AT-2026-0028
JPCERT/CC
2026-09-24
F5
K000162605: BIG-IP APM vulnerability CVE-2026-94127
https://my.f5.com/manage/s/article/K000162605
JPCERT/CC confirms that the product is widely used in Japan. Furthermore, detailed explanations have been published by watchTowr Labs, showing the process leading to remote code execution. Exploit code for this vulnerability may be published in the future, and attacks exploiting this vulnerability may become widespread. If you are using this product, please check the information in "III. Countermeasures" and "V.侵害検出方法" below, as well as the latest information provided by F5, and consider implementing countermeasures along with investigating whether the equipment has been compromised.
BIG-IP APM
- 21 series: 21.1.0
- 17 series: 17.5.0 to 17.5.1, 17.1.0 to 17.1.3
- Check the log messages in "/var/log/apm" and confirm whether the OAuth UserInfo request failure event with log ID "01990004" is repeatedly recorded 10 or more times.
※ Special attention is required if the requests originate from a single source IP address.
- Execute the command "tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed" to output statistics on OAuth failures and check for a sudden increase in unexplained OAuth failures.
- If OAuth failures are observed consecutively in a short period, check the audit log messages in "/var/log/audit" for the same time period.
- Check whether TMM core files have been generated.
※ If TMM enters a loop state, the SOD daemon sends SIGABRT, which results in the generation of a core file. If you find such a file, please investigate it along with other events.
In addition, if you confirm the above traces, please also check the following points based on the attack methods demonstrated in the detailed explanation published by watchTowr Labs:
- Check whether manipulated HTTP requests containing abnormally long Authorization headers are being sent to "/f5-oauth2/v1/userinfo".
※ Manipulated HTTP requests may also be sent to other paths.
- Confirm that the file "/etc/bigstart/scripts/tmm.finish" has not been tampered with.
watchTowr Labs
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
https://labs.watchtowr.com/is-this-a-joke-in-the-auth-header-f5-big-ip-unauth-heap-overflow-to-rce-cve-2026-94127/
If you have any information regarding this matter, please contact JPCERT/CC.
Japan Cybersecurity Coordination Center (JPCERT/CC)
Cybersecurity Coordination Group
Email: ew-info@jpcert.or.jp
JPCERT/CC
2026-09-24
I. Overview
F5 released an advisory on September 22, 2026, regarding a heap-based buffer overflow vulnerability (CVE-2026-94127) in BIG-IP APM (Access Policy Manager). If the product is configured as an OAuth Authorization Server and APM access policies and OAuth profiles are set on virtual servers, exploiting this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code. F5 states that this vulnerability is being exploited. F5
K000162605: BIG-IP APM vulnerability CVE-2026-94127
https://my.f5.com/manage/s/article/K000162605
JPCERT/CC confirms that the product is widely used in Japan. Furthermore, detailed explanations have been published by watchTowr Labs, showing the process leading to remote code execution. Exploit code for this vulnerability may be published in the future, and attacks exploiting this vulnerability may become widespread. If you are using this product, please check the information in "III. Countermeasures" and "V.侵害検出方法" below, as well as the latest information provided by F5, and consider implementing countermeasures along with investigating whether the equipment has been compromised.
II. Affected Products
The products and versions affected by this vulnerability are as follows. Please check the latest information provided by the developer for details. BIG-IP APM
- 21 series: 21.1.0
- 17 series: 17.5.0 to 17.5.1, 17.1.0 to 17.1.3
III. Countermeasures
Please check the latest information provided by F5 and consider applying hotfixes to correct the vulnerability if you are using an affected version. IV. Mitigation
If hotfixes cannot be applied, F5 provides iRules applicable to BIG-IP APM virtual servers as a temporary measure to mitigate the impact of this vulnerability. Please check the latest information provided by F5 for details. V. Detection Methods
Detection methods are provided by F5. When checking for compromise, please verify the following points. If these traces are found, we recommend further investigation based on the possibility that the product has been compromised.
- Check the log messages in "/var/log/apm" and confirm whether the OAuth UserInfo request failure event with log ID "01990004" is repeatedly recorded 10 or more times.
※ Special attention is required if the requests originate from a single source IP address.
- Execute the command "tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed" to output statistics on OAuth failures and check for a sudden increase in unexplained OAuth failures.
- If OAuth failures are observed consecutively in a short period, check the audit log messages in "/var/log/audit" for the same time period.
- Check whether TMM core files have been generated.
※ If TMM enters a loop state, the SOD daemon sends SIGABRT, which results in the generation of a core file. If you find such a file, please investigate it along with other events.
In addition, if you confirm the above traces, please also check the following points based on the attack methods demonstrated in the detailed explanation published by watchTowr Labs.
- Check whether manipulated HTTP requests containing abnormally long Authorization headers are being sent to "/f5-oauth2/v1/userinfo".
※ Manipulated HTTP requests may also be sent to other paths.
- Confirm that the file "/etc/bigstart/scripts/tmm.finish" has not been tampered with.
VI. Reference Information
watchTowr Labs
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
https://labs.watchtowr.com/is-this-a-joke-in-the-auth-header-f5-big-ip-unauth-heap-overflow-to-rce-cve-2026-94127/
If you have any information regarding this matter, please contact JPCERT/CC.
Japan Cybersecurity Coordination Center (JPCERT/CC)
Cybersecurity Coordination Group
Email: ew-info@jpcert.or.jp
