Cyber Security News

Critical F5 BIG-IP APM Flaw Actively Exploited for Remote Code Execution

F5 has disclosed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) that is already being exploited in the wild.

This vulnerability, tracked as CVE-2026-94127, allows unauthenticated attackers to execute code on affected BIG-IP systems when a vulnerable OAuth configuration is exposed through an APM virtual server.

Published on September 22, F5’s advisory classifies the issue as a CWE-122 heap-based buffer overflow. It assigns it a CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3. Internally, F5 tracks the vulnerability as BIG-IP ID 2524777.

F5 BIG-IP APM Flaw

CVE-2026-94127 affects BIG-IP APM deployments that have both an access policy and an OAuth profile configured on the same virtual server.

The vulnerable condition arises when APM is configured to function as an OAuth Authorization Server. F5 reported that specially crafted malicious traffic can trigger remote code execution under these circumstances. Since authentication is not required, internet-facing APM systems are particularly high-priority targets for defenders.

Deployments using BIG-IP APM solely as an OAuth Client or Resource Server are not affected, provided they do not have OAuth Authorization Server profiles configured.

This issue is classified as a data-plane vulnerability, and F5 noted that it does not expose the BIG-IP control plane. Appliance-mode BIG-IP systems remain vulnerable if they meet the specified configuration requirements.

Affected Versions and Fixes

The component affected is APM OAuth. F5 has identified the following vulnerable BIG-IP APM releases:

BIG-IP APM branchVulnerable versionsAvailable fix
21.x21.1.0Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso
17.5.x17.5.0 through 17.5.1Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso
17.1.x17.1.0 through 17.1.3Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso

F5 said engineering hotfixes are available through F5 Downloads and include fixes incorporated in BIG-IP Hardened Releases. Additionally, BIG-IP Next, BIG-IQ Centralized Management, F5 Distributed Cloud services, F5OS, NGINX products, and F5 AI Gateway are not vulnerable to this issue.

F5 has published behavioral indicators that administrators should investigate. Attack patterns may include repeated OAuth authentication failures, suspicious command activity, and a TMM process crash resulting in a SIGABRT signal.

A potentially relevant entry in /var/log/apm contains an “invalid_token” error related to a failed UserInfo request. F5 considers sustained repetition- at least 10 related events in one log, particularly from a single IP address- a medium-confidence indicator that requires review. Administrators can also inspect OAuth failure statistics using the command:

tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed

An unexplained increase in total_failed requests, followed by suspicious audit-log activity or TMM core files, should prompt immediate incident-response investigation.

Organizations should urgently identify BIG-IP APM virtual servers configured as OAuth Authorization Servers, apply the relevant F5 engineering hotfix, and review authentication, audit, and TMM crash logs for signs of exploitation.

If immediate patching is not possible, F5 recommends applying a mitigation iRule to the affected APM virtual servers; customers must contact F5 Support to obtain this rule.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago