Full Report
F5 security advisory (AV26-949)
Analysis Summary
# Vulnerability: BIG-IP APM Remote Code Execution
## CVE Details
- **CVE ID:** CVE-2026-94127
- **CVSS Score:** 9.8 (Critical) *(Based on standard severity for exploited RCE in APM components)*
- **CWE:** Not specified in the advisory (Likely related to Memory Corruption or Improper Input Validation)
## Affected Systems
- **Products:** F5 BIG-IP (specifically Access Policy Manager - APM)
- **Versions:**
- 21.1.0 through Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
- 17.5.0 through Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
- 17.1.0 through Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
- **Configurations:** Systems running BIG-IP APM with active traffic processing.
## Vulnerability Description
While specific technical internals are reserved for authenticated vendor customers, the vulnerability involves a flaw in the BIG-IP Access Policy Manager (APM). The flaw allows an unauthenticated attacker with network access to the BIG-IP system to potentially execute arbitrary code or bypass security policies.
## Exploitation
- **Status:** **Exploited in the wild.** F5 has confirmed active exploitation of this flaw.
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
## Remediation
### Patches
F5 recommends upgrading to the following fixed versions (or newer):
- **BIG-IP 21.x:** Upgrade to 21.1.1 or the latest engineering hotfix provided by F5 support.
- **BIG-IP 17.5.x:** Upgrade to 17.5.2 or the latest engineering hotfix.
- **BIG-IP 17.1.x:** Upgrade to 17.1.4 or the latest engineering hotfix.
### Workarounds
- Limit access to the BIG-IP management interface (ConfigSync, High Availability, and REST API) to trusted networks only.
- Disable unnecessary APM profiles if not in active use.
- Refer to F5 K-article K000162605 for specific configuration hardening.
## Detection
- **Indicators of Compromise:** Monitor for unusual administrative account creation, unexpected modifications to `/config/bigip.conf`, and unauthorized outbound network connections from the BIG-IP management or TMM interfaces.
- **Detection Methods:** Review BIG-IP logs (`/var/log/apm` and `/var/log/ltm`) for segmentation faults or unusual process restarts associated with the APM service.
## References
- **Vendor Advisory:** [https[:]//my.f5.com/manage/s/article/K000162605]
- **F5 Security Notifications:** [https[:]//my.f5.com/manage/s/article/K12201527#currentyear]
- **Cyber Centre Bulletin:** [https[:]//www.cyber.gc.ca/en/alerts-advisories/f5-security-advisory-av26-949]