CVE-2026-94127
BIG-IP APM OAuth vulnerability
Description
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
In plain language
AI Act nowBIG-IP systems using APM as an OAuth Authorization Server are at critical risk and need urgent action.
Unauthenticated network-based remote code execution in F5 BIG-IP APM caused by a CWE-122 memory error when an access policy and OAuth Authorization Server profile are configured on a virtual server.
What to do now
- Check whether each BIG-IP virtual server uses APM with both an access policy and an OAuth profile configured as an OAuth Authorization Server.
- If it does, identify the BIG-IP software branch currently installed and assess whether the affected virtual server is exposed to untrusted networks.
- Install the applicable F5 hotfix: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, or Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.
- If the hotfix cannot be installed immediately, open an F5 support ticket to request the available iRule workaround.
- Preserve relevant BIG-IP logs and have IT investigate the device for suspicious activity.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)en·watchTowr Labs·
- Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instancesen-us·Help Net Security· Exploited Check Point Management Server rce
- F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Serversen·The Hacker News· Exploited BIG-IP Access Policy Manager network-edge
- Critical F5 BIG-IP Vulnerability Exploited as Zero-Dayen-us·SecurityWeek· Exploited BIG-IP Access Policy Manager network-edge
- F5 patches BIG-IP APM zero-day flaw exploited in RCE attacksen-us·BleepingComputer· Exploited BIG-IP Access Policy Manager network-edge
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-94127 and every CVE in our database. Create a free account — no credit card required.
Create Free Account