F5 BIG-IP APM Zero-Day CVE-2026-94127 Hits OAuth Servers
Security / news
F5 BIG-IP APM Zero-Day CVE-2026-94127 Hits OAuth Servers
The heap overflow was exploited before F5 shipped hotfixes on Sept. 22, and only appliances acting as an OAuth authorization server are exposed.
A remote, unauthenticated attacker can trigger a heap overflow in F5's BIG-IP Access Policy Manager (APM) when the appliance is configured as an OAuth authorization server, and attackers were already doing it before F5 had a fix. The flaw, CVE-2026-94127, is rated 9.8 out of 10 on the CVSS severity scale. F5 published advisory K000162605 on Sept. 22, 2026.
CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day and set a Sept. 25 deadline for federal civilian agencies, according to SOC Prime. CSO Online reported on Sept. 23 that the bug was "already under active exploitation in the wild" before the patch existed. I could not load F5's own advisory page, which returned only a loading message, so the details below come from those two reports.
Who is exposed
The preconditions are narrow, and they matter more than the score. The virtual server needs both an APM access policy and an OAuth profile, and APM has to be acting as the OAuth authorization server. Deployments that use APM only as an OAuth client or resource server are not affected unless that configuration is also present. Appliance mode systems are vulnerable when the configuration is present.
The flaw is a heap-based buffer overflow (CWE-122) in the data plane, in the Traffic Management Microkernel, or TMM. SOC Prime notes that locking down the management interface therefore does not remove the risk. It lists a CVSS 3.1 score of 9.8 and a CVSS 4.0 score of 9.3.
Shadowserver tracks more than 15,000 internet-exposed BIG-IP APM deployments, about 5,000 each in North America and Europe, CSO Online reported. That counts APM, not the subset configured as an OAuth server, so it is a ceiling on exposure, not an estimate of it.
Affected builds and hotfixes
| Branch | Affected | Hotfix |
|---|---|---|
| 21.1 | 21.1.0 | Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso |
| 17.5 | 17.5.0 to 17.5.1 | Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso |
| 17.1 | 17.1.0 to 17.1.3 | Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso |
The fixes are engineering hotfix images, not point releases. Releases that have reached end of technical support were not evaluated, and SOC Prime says they should not be assumed safe. An iRule, F5's traffic-scripting language, is available as a stopgap, but it has to be requested from F5 Support. CISA recommends it only until the hotfix is installed.
Detection is a correlation problem
F5's guidance, as quoted by CSO Online, is that "multiple OAuth authentication failures, followed by suspicious commands, shortly followed by a TMM SIGABRT" should trigger human review. No single signal is enough. Ten or more OAuth failure messages from one address in a short window warrants a look.
Three checks are concrete:
- Run
tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failedand look for an unexplained rise intotal_failed. - Search
/var/log/apmfor repeated "invalid token" UserInfo failures, and/var/log/auditfor commands shortly after bursts of them. - Look for TMM core files, since exploitation can make TMM loop and crash.
TMM crashes have benign causes too, so treat them as one input. SOC Prime advises preserving logs and forensic evidence before patching or restarting, because applying the hotfix does not show whether the appliance was already compromised.
What is still unknown
Neither report names a threat actor, a ransomware link, a victim count or a target industry, and SOC Prime says the date of first exploitation was not disclosed. It also found no public proof of concept or exploit module at publication. CSO Online adds that earlier in September researchers reported a Linux rootkit aimed at BIG-IP APM, tied to the older CVE-2025-5352, which shows the product is under sustained attention.
This follows a pattern The Terminal has covered on other vendors' gear, including the Cling botnet and the Apple CoreGraphics zero-day. The practical step is a lookup: find out whether any BIG-IP virtual server carries both an APM policy and an OAuth profile, and if one does, install the hotfix for 21.1.0, 17.5.1 or 17.1.3 and read the logs first.
Sources
More in Security
- 01CISA Gave Agencies Three Days for Five 2015-2023 Bugs, and Four Come With a Forensic Triage OrderThe October 8 additions to the exploited-vulnerabilities catalogue show how BOD 26-04 has changed what a deadline means: the patch is the smaller job.
- 02Apple's CoreGraphics Zero-Day CVE-2026-86950 Has a CISA Deadline of October 13, Not the October 2 Being ReportedTrade coverage gives a three-day federal deadline. The catalogue entry itself carries 14 days and no forensic-triage flag.
- 03Rejetto HFS CVE-2026-61500, Found With Anthropic's Mythos, Was Probed One Day After DisclosureA predictable session-signing key lets an unauthenticated attacker forge an HFS admin cookie and run server-side JavaScript; HFS 3.2.1 has carried the fix since July.
- 04Exchange CVE-2026-96940 Lets Any Mailbox User Read Others' Mail, and Patched Servers Need V2Microsoft's out-of-band September V2 update closes an 8.8-rated authorization flaw in on-premises Exchange, with four KBs and a support cliff for 2016 and 2019.