Actively Exploited Heap Overflow In F5 BIG-IP APM Enables Unauthenticated RCE

F5 BIG-IP APM is vulnerable when configured as an OAuth authorization server; client and resource-server deployments are unaffected.

Published on Sep 23, 2026
Actively Exploited Heap Overflow In F5 BIG-IP APM Enables Unauthenticated RCE

F5 has disclosed an actively exploited heap-based buffer overflow in BIG-IP Access Policy Manager (APM) that lets an unauthenticated attacker achieve Remote Code Execution (RCE). F5 has confirmed CVE-2026-94127 is being actively exploited.

Exposure depends on configuration. The flaw is present when an APM access policy and an OAuth profile are configured on a virtual server with APM acting as an OAuth authorization server, and F5 said deployments using APM strictly as an OAuth client or resource server are not affected.

Vulnerable releases are 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3, while F5’s other products are not affected. Systems in Appliance mode are also vulnerable, and F5 said it is a data plane issue with no control plane exposure.

F5 rated the flaw critical, at 9.8 under CVSS v3.1 and 9.3 under v4.0, and classified it as CWE-122. The company said it discovered the flaw internally, and it has not said who is exploiting it or how widely.

The company warned that repeated OAuth authentication failures, followed by suspicious commands and then a SIGABRT for the Traffic Management Microkernel (TMM), close together in time, should prompt human review.

No single indicator confirms compromise, but the combination and frequency have correlated with attacks.

Detection and Remediation

The OAuth failures are a medium-confidence signal, and repetition is what counts: 10 or more in one log, especially from a single IP address, warrants investigation. F5 advised checking audit logs around those timestamps, watching for an unexplained rise in OAuth failure counters, and investigating any TMM core files.

F5 has fixed the flaw in engineering hotfixes for the 21.1, 17.5, and 17.1 release lines, listed in its advisory and available through F5 Downloads. As an interim measure, administrators can apply an iRule to the affected APM virtual server, which F5 Support supplies on request.

The Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on Sept. 22, alongside two Check Point flaws and one in Arista’s VeloCloud Orchestrator.

Under CISA’s Binding Operational Directive 26-04, federal civilian agencies must prioritize fixing flaws like this one, and the directive sets out when they must check whether systems were compromised before a patch was applied.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Alessandro Mascellino
Alessandro Mascellino Cybersecurity Reporter

Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.