Mastodon Mastodon Mastodon Mastodon

CVE-2026-94127: critical F5 BIG-IP APM vulnerability exploited for remote code execution on OAuth servers

Photo of author

CyberSecureFox Editorial Team

Published:

F5 has reported active exploitation of a critical vulnerability, CVE-2026-94127, in the BIG-IP Access Policy Manager (APM) module that allows attackers to execute arbitrary code on the target system without authentication. The vulnerability affects deployments where APM acts as an OAuth authorization server. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 22 September 2026, setting a deadline of 25 September for U.S. federal civilian agencies to implement mitigations. Organizations using BIG-IP APM with an OAuth Authorization Server profile must immediately install F5 engineering hotfixes or apply the temporary iRule-based workaround.

Technical characteristics of the vulnerability

CVE-2026-94127 is a heap buffer overflow (CWE-122). F5, as the CNA authority, has assigned the vulnerability a score of 9.8 under CVSS v3.1 and 9.3 under CVSS v4.0 — both correspond to the Critical level.

The key feature of this vulnerability is that it is a data-plane issue, not a control-plane one. Malicious traffic is sent directly to the virtual server that processes OAuth requests. This means that restricting access to the BIG-IP management interface does not protect against exploitation. Systems in Appliance mode are also vulnerable.

Affected versions and fixes

According to the CVE record, the following BIG-IP APM branches are vulnerable:

  • 21.1.0 — before Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
  • 17.5.0 — before Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
  • 17.1.0 — before Hotfix-BIGIP-17.1.3.5.0.41.14-ENG

F5 did not assess versions that have reached End of Technical Support status. Their status should be considered unknown rather than safe — this is stated explicitly in the CNA record.

Scope of the vulnerable configuration

An important clarification that F5 added to the CVE record on 23 September at 00:45 UTC: the vulnerability affects only deployments where APM functions as an OAuth authorization server (OAuth Authorization Server). According to the F5 documentation, the vulnerable configuration assumes the presence of an OAuth Authorization Server profile created under Access → Federation → OAuth Authorization Server → OAuth Profile and bound to an access profile on the virtual server.

Deployments where APM is used exclusively as an OAuth client or resource server (without authorization server profiles) are not affected. Early descriptions from CISA and CERT-EU used a broader wording — “an access profile and OAuth profile on a virtual server” — but the updated CNA record narrows the exploitation condition specifically to the authorization server role.

Relation to previous vulnerabilities

It is worth noting that another APM vulnerability — CVE-2025-53521 — was added to the CISA KEV catalog back in March 2026. Fixes for it in the 17.1 and 17.5 branches (versions 17.1.3 and 17.5.1.3) fall within the range of versions affected by CVE-2026-94127. A system updated to these builds still requires a new hotfix if APM on it acts as an OAuth authorization server.

What is known about exploitation

According to F5, the vulnerability is being actively exploited. However, neither the CVE record, nor the CISA KEV catalog, nor the CERT-EU advisory disclose the scale of the attacks, the identity of the attackers, or the list of affected organizations. Independent attack telemetry is not provided in the available materials.

Detecting compromise

According to the CERT-EU advisory, which refers to F5 indicators, the sequence of events that requires manual system inspection includes:

  • APM log: repeated failed UserInfo requests in /var/log/apm with the error description “The access token is invalid” — particularly 10 or more requests from a single IP address in a short period
  • OAuth counter: unexplained growth of the total_failed value when running the command tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed
  • Audit log: suspicious commands in /var/log/audit during the period that coincides with the above failures
  • TMM dumps: TMM process core files triggered by a SIGABRT signal from the SOD daemon after TMM enters a loop

The trigger for investigation is precisely the sequence: mass failed OAuth authentications → suspicious commands in the audit log → TMM process SIGABRT shortly thereafter. These indicators are taken from the CERT-EU advisory and have not been independently verified as part of this analysis.

Response recommendations

The highest patching priority should be given to virtual servers with an OAuth Authorization Server profile that process external traffic. Restricting access to the BIG-IP management interface is not a mitigation for this vulnerability.

  1. Immediately: determine whether APM is being used as an OAuth authorization server (Access → Federation → OAuth Authorization Server → OAuth Profile)
  2. If you can install the hotfix right away: apply the appropriate engineering hotfix for your branch
  3. If installing the hotfix is not immediately possible: request the iRule workaround via F5 support. CISA recommended that agencies apply the iRule as the first step to preserve the possibility of forensic analysis
  4. Check for indicators of compromise based on the sequence of events described above
  5. Preserve forensic data before applying fixes — CERT-EU specifically recommends this order of actions
  6. If signs of compromise are found: initiate your incident response procedure

Neither F5, nor CISA, nor CERT-EU clarify whether installing the hotfix removes access already obtained by an attacker. This means that patching alone may not be sufficient — a full check of the system for signs of compromise is required.

Organizations with BIG-IP APM acting as an OAuth Authorization Server should treat this vulnerability as requiring emergency response: the CVSS score of 9.8, confirmed exploitation, lack of protection through management interface restriction, and the three-day CISA deadline all point to maximum priority. Install the hotfix for your branch or apply the iRule, check the APM and audit logs for the described sequence of indicators, and be prepared to conduct incident response if anomalies are detected.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.