CVE-2026-94127: Critical F5 BIG-IP APM Flaw Under Active Exploitation
F5 has confirmed in-the-wild exploitation of CVE-2026-94127, a CVSS 9.8 unauthenticated heap-based buffer overflow in the OAuth component of BIG-IP Access Policy Manager (APM) that leads to remote code execution.
TA2026280Published September 23, 2026Admiralty A1TA2026280A1CVE-2026-941279.8 v3.1 / 9.3 v4.0CWE-122Summary
F5 has disclosed CVE-2026-94127, a critical unauthenticated remote code execution flaw (CVSS 9.8) in the OAuth component of BIG-IP Access Policy Manager (APM), and has confirmed it is being actively exploited in the wild. The flaw is a heap-based buffer overflow that can be triggered with specially crafted traffic.
CVE-2026-94127 affects F5 BIG-IP APM versions 21.1.0, 17.5.0 - 17.5.1 and 17.1.0 - 17.1.3, but only on virtual servers where APM acts as an OAuth Authorization Server. Emergency hotfixes are available for all affected branches, and a vendor-supplied iRule mitigation can be used where immediate patching is not possible.
Affected Products
CVE
| CVE | Name | Affected Product | Zero-Day | CISA KEV | Patch |
|---|---|---|---|---|---|
CVE-2026-94127 | F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability | F5 BIG-IP Access Policy Manager (APM) | Yes | Yes | Available |
Vulnerability Details
- #01
CVE-2026-94127is a critical heap-based buffer overflow (CWE-122) in the OAuth component of F5 BIG-IP Access Policy Manager (APM). It allows an unauthenticated remote attacker to execute arbitrary code on affected appliances. The flaw carries a CVSS v3.1 score of9.8and a CVSS v4.0 score of9.3, and the vendor has confirmed active exploitation in the wild at the time of disclosure onSeptember 22, 2026. The vulnerable releases are BIG-IP APM21.1.0,17.5.0through17.5.1, and17.1.0through17.1.3. - #02
Exposure depends on configuration rather than on the mere presence of APM. Only virtual servers that carry both an APM access policy and an OAuth profile, with APM acting as an OAuth Authorization Server, are vulnerable. Deployments that use APM solely as an OAuth client or resource server are not affected. The flaw resides in the data plane and does not expose the control plane, so restricting access to the management interface offers no protection, and systems running in Appliance mode remain vulnerable. The specific code path responsible for the overflow has not been disclosed.
- #03
Exploitation of
CVE-2026-94127requires only specially crafted traffic sent to an exposed virtual server, with no credentials or user interaction. A successful attack gives the attacker code execution on a perimeter authentication gateway that controls access to downstream applications. No threat actor has been attributed, and no atomic indicators of compromise have been released. Vendor detection guidance instead describes a behavioural sequence: repeated OAuth UserInfo failures with invalid-token errors, followed by suspicious commands in the audit log, and then a Traffic Management Microkernel (TMM) crash. - #04
Emergency hotfixes are available for all three affected BIG-IP APM branches. Where immediate patching is not possible, an iRule mitigation can be obtained through vendor support to reduce exposure until the hotfix is installed.
Vulnerability
| CVE ID | Affected Products | Affected CPE | CWE ID |
|---|---|---|---|
CVE-2026-94127 | F5 BIG-IP APM (17.1.0 - 17.1.3, 17.5.0 - 17.5.1, 21.1.0) | cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:* | CWE-122 |
Recommendations
- 01Apply the Emergency Hotfix Immediately
Install the engineering hotfix that matches the installed BIG-IP APM branch (
17.1.x,17.5.xor21.x) from F5 Downloads, or move to the corresponding hardened release that already incorporates the fix. Given confirmed exploitation and the absence of any authentication requirement, patching should be treated as an emergency change rather than scheduled into a routine maintenance window. - 02Preserve Forensic Evidence Before Remediation
Before patching, rebooting or reconfiguring affected appliances, collect and securely retain
/var/log/apm,/var/log/auditand any TMM core files so that exploitation can still be assessed afterwards. Remediation activity can overwrite or rotate the very artefacts needed to confirm whether a device was compromised. - 03Identify Exposed OAuth Authorization Server Configurations
Enumerate every BIG-IP APM virtual server that has both an access policy and an OAuth profile attached and determine whether APM is acting as an OAuth Authorization Server on it. These virtual servers, particularly those reachable from the internet, define the true exposure and should be prioritised for patching and threat hunting.
- 04Deploy the Vendor Mitigation iRule Where Patching Is Delayed
If the hotfix cannot be installed immediately, contact F5 Support to obtain the iRule-based mitigation and apply it to every affected APM virtual server. Treat this strictly as a temporary control, validate that OAuth flows continue to function after it is applied, and retire it only once the hotfix is in place.
MITRE ATT&CK TTPs
References & Patch Links
Patch Link
- F5 K000162605
https://my.f5.com/manage/s/article/K000162605
