DEV Community

kozhevniko
kozhevniko

Posted on

F5 BIG-IP APM CVE-2026-94127: an unauthenticated RCE that a hardening setting does not stop

F5 BIG-IP APM CVE-2026-94127: an unauthenticated RCE that a hardening setting does not stop

A load balancer can be an attack surface, not only a traffic cop. CVE-2026-94127 in F5 BIG-IP Access Policy Manager (APM) shows why that distinction matters at the edge of the network.

What the vulnerability is

F5 published advisory K000162605 for CVE-2026-94127 on 2026-09-22, and CISA added the CVE to its Known Exploited Vulnerabilities catalog the same day. F5 rates the flaw 9.8 under CVSS v3.1 and 9.3 under CVSS v4.0. The defect is a heap-based buffer overflow, classified as CWE-122, in the data plane path that handles OAuth traffic.
An unauthenticated attacker can send crafted network traffic to a vulnerable virtual server and corrupt memory, which can lead to remote code execution. No credentials and no user interaction are required.

The configuration condition

The flaw does not affect every BIG-IP deployment. A virtual server is exposed when it runs both an APM access policy and an OAuth profile, and the OAuth authorization server use case is the relevant one. Devices that use APM only as an OAuth client or resource server are outside the affected configuration.
That condition is common in enterprises that terminate single sign-on or remote access at BIG-IP. F5 states that Appliance mode remains exploitable, so the usual hardening posture does not remove the risk. Because the vulnerable code sits in the data plane, restricting the management interface does not block exploitation of an affected virtual server.

Affected versions and fixes

The affected branches are BIG-IP APM 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3. F5 released engineering hotfixes, distributed as Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso. Other BIG-IP modules, BIG-IQ, BIG-IP Next, F5 Distributed Cloud, NGINX products, F5OS, and F5 AI Gateway are not affected. Versions past End of Technical Support were not assessed.

Detection

F5 published indicators of compromise. Investigations should start in the APM logs.

  • Search /var/log/apm for repeated UserInfo failures, such as "Request UserInfo from Source ID (null) IP failed. Error Code (invalid_token)".
  • Check OAuth counters with tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed for unexplained growth in failures.
  • Review /var/log/audit around the failure window for unexpected shell, curl, wget, or interpreter commands.
  • Look for new TMM core files under /shared/core and for TMM restart or SIGABRT events. Because the flaw was exploited before a public fix, installing the hotfix does not reveal whether an attacker already entered. Retrospective hunting over prior logs is the only way to answer that question.

Remediation

Patch first. Where immediate patching is impossible, F5 support can supply a temporary iRule, and access to the affected virtual server should be narrowed to necessary sources. Teams should inventory every BIG-IP APM virtual server and identify which ones combine an access policy with an OAuth authorization server profile, then treat internet-facing instances as the highest priority.

Exposure context

At the time of writing, ZoomEye reported 1,576,057 matches for app="F5 BIG-IP" across all asset types when queried on 2026-09-30 (UTC). That count describes assets matching the product fingerprint, not confirmed vulnerable or OAuth-configured systems, so it should be read as the size of the searchable footprint rather than a measure of impacted hosts.

References

  • F5 security advisory K000162605 (CVE-2026-94127).
  • CISA Known Exploited Vulnerabilities catalog entry for CVE-2026-94127, added 2026-09-22.
  • F5 BIG-IP APM OAuth analysis and IoC walkthrough, friday-go.icu.

Top comments (0)