Security researchers have identified a significant vulnerability in F5’s BIG-IP Access Policy Manager (APM), allowing attackers to execute code without authentication. The flaw, known as CVE-2026-94127, impacts systems where APM functions as an OAuth authorization server. F5 issued an advisory on September 22, 2026, and provided engineering hotfixes to address the issue.
Understanding the Vulnerability
The flaw, characterized as a heap-based buffer overflow, is present in configurations where APM’s access policy and an OAuth authorization server profile share the same virtual server. This setup allows specific malicious traffic to lead to remote code execution. F5 assesses the vulnerability at a critical level, rating it 9.8 on the CVSS v3.1 and 9.3 on CVSS v4.0 scales.
Despite the critical nature of the flaw, limiting access to the BIG-IP management interface does not mitigate the risk. Systems operating in ‘Appliance mode’ are similarly vulnerable. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog on the same day, urging federal agencies to implement F5’s recommended mitigations by September 25.
Impact and Affected Versions
The vulnerability impacts specific versions of BIG-IP when APM acts as an OAuth authorization server. Affected versions include 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3, with specific hotfixes available for each. Systems using APM solely as an OAuth client or resource server without an authorization server profile remain unaffected.
F5 updated its records to specify that the flaw is exclusive to authorization server roles. Prior advisories from CISA and CERT-EU described the vulnerability more broadly. Notably, F5 did not evaluate versions that have reached the end of technical support, leaving their vulnerability status uncertain.
Mitigation and Response
F5’s engineering hotfixes are the primary remedy for this vulnerability. Where immediate installation is infeasible, F5 provides an iRule mitigation, accessible through their support channels. CERT-EU recommends preserving forensic evidence, applying the hotfix, and checking for possible compromises before responding to incidents.
CISA advises agencies to prioritize applying the iRule for proactive forensic analysis, followed by installing the final vendor patch. Indicators of compromise include repeated failed OAuth authentication attempts, suspicious audit log entries, and technical management module (TMM) core files signaling potential issues.
While these measures aim to safeguard affected systems, it remains unclear if the hotfix can eliminate existing unauthorized access. Organizations are urged to remain vigilant and ensure their systems are updated promptly.
