Executive Summary
F5 BIG-IP Access Policy Manager (APM) is under confirmed active exploitation for CVE-2026-94127, a critical heap-based buffer overflow (CWE-122) that can allow an unauthenticated attacker to achieve remote code execution when a virtual server is configured with both an APM access policy and an OAuth profile—specifically when BIG-IP APM acts as an OAuth Authorization Server. Deployments that use APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles) are not affected. F5 rates CVSS 3.1 at 9.8 Critical and CVSS 4.0 at 9.3 Critical. CISA added the CVE to the Known Exploited Vulnerabilities catalog on September 22, 2026 (federal due date September 25, 2026; known ransomware campaign use = Unknown; forensic triage required under BOD 26-04). F5 states it discovered the defect internally and has learned the vulnerability has been exploited; engineering hotfixes and a temporary Support-provided iRule are available via advisory K000162605.
This is a data plane issue with no control plane exposure; Appliance mode is also vulnerable. Software versions that have reached End of Technical Support (EoTS) were not evaluated by the vendor.
Technical Information
CVE-2026-94127 is a heap-based buffer overflow in F5 BIG-IP APM. Per the NVD record sourced from F5 PSIRT (f5sirt@f5.com): when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution. The vulnerable condition is present only when BIG-IP APM is configured as an OAuth Authorization Server. No authentication is required for the network path described by the vendor.
F5 (via NVD and SecurityWeek) emphasizes: the BIG-IP system in Appliance mode is also vulnerable; this is a data plane issue with no control plane exposure. EoTS software is out of evaluation scope.
Primary sources reviewed for this advisory (CISA KEV, NVD/F5, CERT-EU 2026-013, CCCS AL26-022) do not publish an explicit MITRE ATT&CK technique ID mapping. This advisory does not invent ATT&CK IDs, actor attribution, or exploit mechanics beyond vendor/CERT impact and remediation facts.
Internet- or WAN-reachable APM OAuth Authorization Server virtual servers are the highest-priority exposure. Restrict management interfaces to trusted administrative networks (CCCS AL26-022).
Affected Product Versions
Vendor / product: F5 — BIG-IP Access Policy Manager (APM).
| Branch | Affected (as sourced) | Fixed |
|---|---|---|
| BIG-IP APM 17.1.x | 17.1.0 through 17.1.3 when APM access policy + OAuth profile on a virtual server (Authorization Server role) | Hotfix-BIGIP-17.1.3.5.0.41.14-ENG |
| BIG-IP APM 17.5.x | 17.5.0 through 17.5.1 under the same configuration | Hotfix-BIGIP-17.5.1.9.0.160.12-ENG |
| BIG-IP APM 21.1.x | 21.1.0 under the same configuration | Hotfix-BIGIP-21.1.0.2.0.30.22-ENG |
Configuration notes:
- Vulnerable only as OAuth Authorization Server (APM access policy + OAuth Authorization Server profile on the same VIP).
- Not affected: APM used strictly as OAuth Client / Resource Server without OAuth authorization server profiles (F5 via NVD).
- Appliance mode is vulnerable; data plane only.
- NVD CPE also lists a 17.0.0–17.1.3 match range; CERT-EU and CCCS tabulate 17.1.0–17.1.3 / 17.5.0–17.5.1 / 21.1.0. Confirm exact build against F5 K000162605 for your installed train.
- F5 (via SecurityWeek): no other products are vulnerable.
- EoTS versions: not evaluated — treat as unsupported risk.
Workaround and Mitigation
- Preserve forensic evidence before or concurrent with remediation where BOD 26-04 / CERT-EU guidance applies (logs, tmctl snapshots, TMM cores) — CERT-EU 2026-013; CISA KEV forensic triage.
- Temporary mitigation: Contact F5 Support to obtain the vendor-provided iRule for affected virtual servers. CISA KEV notes: apply the iRule to allow proactive forensic triage, then install the final vendor patch as soon as possible. The iRule is not published in open advisory text.
- Final fix: Install the applicable engineering hotfix — Hotfix-BIGIP-17.1.3.5.0.41.14-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, or Hotfix-BIGIP-21.1.0.2.0.30.22-ENG (CCCS AL26-022 / CERT-EU / F5 K000162605). Verify version after deployment.
- Inventory: Identify BIG-IP systems where an APM access policy and an OAuth Authorization Server profile share a virtual server (CCCS).
- Harden: Restrict management interfaces to trusted administrative networks; reduce exposure of Auth Server VIPs to untrusted networks where operationally feasible (CCCS).
- CISA KEV requiredAction: Apply vendor mitigations; comply with BOD 26-04 and Forensics Triage Requirements; evaluate internet exposure; discontinue use if mitigations unavailable.
Do not treat the iRule as a permanent substitute for the hotfix.
Indicators of Compromise
Published vendor indicators as relayed by CERT-EU Security Advisory 2026-013 (citing F5 K000162605). SecurityWeek notes F5 published three IoCs whose combined and frequent appearance should be correlated. No exhaustive file hashes, YARA, or ATT&CK-mapped IoC packages in primary sources reviewed. Honest empty beyond the correlation pattern below — do not invent IP lists, hashes, or exploit payloads.
At a high level (CERT-EU / vendor): multiple OAuth authentication failures, followed by suspicious commands, shortly followed by a TMM SIGABRT is the combination that should lead to human review.
| Signal | What to check | Notes |
|---|---|---|
| OAuth auth failures | /var/log/apm for repeated UserInfo failures with Error Code invalid_token / “The access token is invalid,” especially 10 or more from a single IP in a short window | CERT-EU relays vendor log pattern |
| OAuth stats | tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed — unexplained rise in total_failed | CERT-EU / vendor |
| Audit anomalies | /var/log/audit around OAuth-failure timestamps for suspicious commands | CERT-EU / vendor |
| TMM abort / cores | TMM entering a loop → SOD sends SIGABRT; investigate TMM core files (presence alone is not an indicator) | CERT-EU / vendor |
If the correlation pattern appears: begin incident response; preserve evidence; do not assume a hotfix alone proves the environment was clean beforehand.
References
- F5 K000162605: BIG-IP APM vulnerability CVE-2026-94127 — https://my.f5.com/manage/s/article/K000162605
- CISA Known Exploited Vulnerabilities Catalog — CVE-2026-94127 — https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-94127
- CISA KEV JSON feed — https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- CISA BOD 26-04 — https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 implementation / forensics triage guidance — https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- NVD: CVE-2026-94127 — https://nvd.nist.gov/vuln/detail/CVE-2026-94127
- CERT-EU Security Advisory 2026-013, 2026-09-22 — https://www.cert.europa.eu/publications/security-advisories/2026-013/markdown
- CCCS AL26-022, 2026-09-22 — https://www.cyber.gc.ca/en/alerts-advisories/al26-022-vulnerability-impacting-f5-big-ip-access-policy-manager-apm-cve-2026-94127
- SecurityWeek: Critical F5 BIG-IP Vulnerability Exploited as Zero-Day, 2026-09-23 — https://www.securityweek.com/critical-f5-big-ip-vulnerability-exploited-as-zero-day/
Third-Party Risk Bridge: F5 APM as Supplier Identity / OAuth Control Plane
F5 BIG-IP APM often sits in supplier and MSP stacks as the identity and access broker—VPN, SSO, and OAuth Authorization Server token issuance that downstream applications trust. CVE-2026-94127 is unauthenticated RCE on that data-plane path when APM access policy and an OAuth Authorization Server profile share a virtual server, with CISA KEV listing and a three-day federal due date. That makes APM version attestation, Auth Server VIP inventory, iRule-then-hotfix evidence, and CERT-EU/vendor IoC correlation a third-party risk ask—not only “their network appliance.”
Book a demo to see how Rescana tracks vendor identity-plane KEV exposure, version attestation, and compromise-assessment evidence.
Forward this advisory to your TPRM owner if a supplier, MSP, or colo provider terminates OAuth or remote access on F5 BIG-IP APM for your estate—they own the hotfix build, Auth Server VIP exposure, and forensic triage attestation asks above.



