Who is affected
F5 BIG-IP APM is affected when both an access policy and an OAuth profile are configured on the same virtual server. The vulnerability allows unauthenticated remote code execution via a heap-based buffer overflow. The record does not specify which versions of BIG-IP APM are vulnerable, nor does it detail the specific configuration conditions beyond the presence of both policy types.
How to check whether this touches you
- Inventory your F5 BIG-IP APM appliances and document which are internet-facing or reachable from untrusted networks.
- For each BIG-IP APM instance, establish whether both an access policy and an OAuth profile are active on any virtual server; check the configuration management interface or review exported configurations.
- Query BIG-IP APM logs and administrative audit trails for recent configuration changes that introduced or modified OAuth profiles alongside access policies.
- Establish the running software version of each instance via the administrative UI or API; note that F5 may have backported fixes into maintenance releases.
- If you cannot access configuration details directly, engage your F5 account team or use F5's vulnerability assessment tools to map your deployment against the stated conditions.
What to do
- Immediately classify BIG-IP APM instances with both access policies and OAuth profiles as high priority and escalate to your change advisory board.
- Consult F5's vendor guidance (referenced in CISA BOD 26-04) for patch availability and applicability to your version line; do not assume all releases are covered equally.
- If patching cannot be applied within the federal remediation window (2026-09-25), implement network segmentation to restrict unauthenticated access to affected virtual servers; document the compensating control in your risk register.
- Enable detailed logging on affected BIG-IP APM instances, including authentication attempts, policy evaluations, and OAuth transactions; forward logs to a central store with extended retention.
- Schedule a maintenance window and plan for patch deployment; test patches in a staging environment that mirrors your access policy and OAuth configuration before production rollout.
If you find you were exposed
Exploitation of heap-based buffer overflows typically occurs before public disclosure, so assume compromise may predate awareness. Retrieve and analyse BIG-IP APM access logs, authentication logs, and system audit trails from at least 90 days before the public disclosure date (2026-09-22); focus on unusual sequences of unauthenticated requests to affected virtual servers and unexpected process spawning on the appliance. If your log retention is shorter than 90 days, note the gap and prioritise extending retention for future incidents.