F5 has disclosed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) that is already being exploited in the wild.
This vulnerability, tracked as CVE-2026-94127, allows unauthenticated attackers to execute code on affected BIG-IP systems when a vulnerable OAuth configuration is exposed through an APM virtual server.
Published on September 22, F5’s advisory classifies the issue as a CWE-122 heap-based buffer overflow. It assigns it a CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3. Internally, F5 tracks the vulnerability as BIG-IP ID 2524777.
CVE-2026-94127 affects BIG-IP APM deployments that have both an access policy and an OAuth profile configured on the same virtual server.
The vulnerable condition arises when APM is configured to function as an OAuth Authorization Server. F5 reported that specially crafted malicious traffic can trigger remote code execution under these circumstances. Since authentication is not required, internet-facing APM systems are particularly high-priority targets for defenders.
Deployments using BIG-IP APM solely as an OAuth Client or Resource Server are not affected, provided they do not have OAuth Authorization Server profiles configured.
This issue is classified as a data-plane vulnerability, and F5 noted that it does not expose the BIG-IP control plane. Appliance-mode BIG-IP systems remain vulnerable if they meet the specified configuration requirements.
Affected Versions and Fixes
The component affected is APM OAuth. F5 has identified the following vulnerable BIG-IP APM releases:
| BIG-IP APM branch | Vulnerable versions | Available fix |
|---|---|---|
| 21.x | 21.1.0 | Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso |
| 17.5.x | 17.5.0 through 17.5.1 | Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso |
| 17.1.x | 17.1.0 through 17.1.3 | Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso |
F5 said engineering hotfixes are available through F5 Downloads and include fixes incorporated in BIG-IP Hardened Releases. Additionally, BIG-IP Next, BIG-IQ Centralized Management, F5 Distributed Cloud services, F5OS, NGINX products, and F5 AI Gateway are not vulnerable to this issue.
F5 has published behavioral indicators that administrators should investigate. Attack patterns may include repeated OAuth authentication failures, suspicious command activity, and a TMM process crash resulting in a SIGABRT signal.
A potentially relevant entry in /var/log/apm contains an “invalid_token” error related to a failed UserInfo request. F5 considers sustained repetition- at least 10 related events in one log, particularly from a single IP address- a medium-confidence indicator that requires review. Administrators can also inspect OAuth failure statistics using the command:
tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed An unexplained increase in total_failed requests, followed by suspicious audit-log activity or TMM core files, should prompt immediate incident-response investigation.
Organizations should urgently identify BIG-IP APM virtual servers configured as OAuth Authorization Servers, apply the relevant F5 engineering hotfix, and review authentication, audit, and TMM crash logs for signs of exploitation.
If immediate patching is not possible, F5 recommends applying a mitigation iRule to the affected APM virtual servers; customers must contact F5 Support to obtain this rule.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…