Critical F5 BIG-IP APM Flaw Actively Exploited for Remote Code Execution
F5 says CVE-2026-94127, a critical unauthenticated BIG-IP APM RCE, is already exploited in the wild.
F5 disclosed CVE-2026-94127, a heap-based buffer overflow in BIG-IP Access Policy Manager scored CVSS 9.8 (v3.1) and 9.3 (v4.0), and said it is already exploited. Unauthenticated attackers can execute code when an APM virtual server is configured as an OAuth Authorization Server. Affected releases include 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3, with engineering hotfixes available. Indicators include repeated OAuth failures, suspicious command activity, and TMM crashes producing SIGABRT.
- CVE-2026-94127 is unauthenticated RCE, CVSS 9.8, actively exploited.
- Only APM virtual servers acting as OAuth Authorization Servers are affected.
- Hotfixes cover BIG-IP 21.1.0, 17.5.x, and 17.1.x branches.
- BIG-IP Next, BIG-IQ, NGINX, and F5OS are not vulnerable.
- F5 offers a support-only iRule if immediate patching is impossible.
Vulnerabilities mentionedAll →
- CVE-2026-941279.32%Unauthenticated Heap-Overflow RCE in F5 BIG-IP APM with OAuth Profilepublished · F5 BIG-IP (Access Policy Manager) KEV PoC ×2
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article504 words · extracted from gbhackers.com · click to collapse
F5 has disclosed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) that is already being exploited in the wild.
This vulnerability, tracked as CVE-2026-94127, allows unauthenticated attackers to execute code on affected BIG-IP systems when a vulnerable OAuth configuration is exposed through an APM virtual server.
Published on September 22, F5’s advisory classifies the issue as a CWE-122 heap-based buffer overflow. It assigns it a CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3. Internally, F5 tracks the vulnerability as BIG-IP ID 2524777.
F5 BIG-IP APM Flaw
CVE-2026-94127 affects BIG-IP APM deployments that have both an access policy and an OAuth profile configured on the same virtual server.
The vulnerable condition arises when APM is configured to function as an OAuth Authorization Server. F5 reported that specially crafted malicious traffic can trigger remote code execution under these circumstances. Since authentication is not required, internet-facing APM systems are particularly high-priority targets for defenders.
Deployments using BIG-IP APM solely as an OAuth Client or Resource Server are not affected, provided they do not have OAuth Authorization Server profiles configured.
This issue is classified as a data-plane vulnerability, and F5 noted that it does not expose the BIG-IP control plane. Appliance-mode BIG-IP systems remain vulnerable if they meet the specified configuration requirements.
Affected Versions and Fixes
The component affected is APM OAuth. F5 has identified the following vulnerable BIG-IP APM releases:
| BIG-IP APM branch | Vulnerable versions | Available fix |
|---|---|---|
| 21.x | 21.1.0 | Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso |
| 17.5.x | 17.5.0 through 17.5.1 | Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso |
| 17.1.x | 17.1.0 through 17.1.3 | Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso |
F5 said engineering hotfixes are available through F5 Downloads and include fixes incorporated in BIG-IP Hardened Releases. Additionally, BIG-IP Next, BIG-IQ Centralized Management, F5 Distributed Cloud services, F5OS, NGINX products, and F5 AI Gateway are not vulnerable to this issue.
F5 has published behavioral indicators that administrators should investigate. Attack patterns may include repeated OAuth authentication failures, suspicious command activity, and a TMM process crash resulting in a SIGABRT signal.
A potentially relevant entry in /var/log/apm contains an “invalid_token” error related to a failed UserInfo request. F5 considers sustained repetition- at least 10 related events in one log, particularly from a single IP address- a medium-confidence indicator that requires review. Administrators can also inspect OAuth failure statistics using the command:
tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed
An unexplained increase in total_failed requests, followed by suspicious audit-log activity or TMM core files, should prompt immediate incident-response investigation.
Organizations should urgently identify BIG-IP APM virtual servers configured as OAuth Authorization Servers, apply the relevant F5 engineering hotfix, and review authentication, audit, and TMM crash logs for signs of exploitation.
If immediate patching is not possible, F5 recommends applying a mitigation iRule to the affected APM virtual servers; customers must contact F5 Support to obtain this rule.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.