One OAuth Profile Can Turn BIG-IP APM Into a Remote Code Execution Target
The product guarding access to the network may now be the way into it.
F5 has confirmed active exploitation of CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager. Under the affected configuration, an unauthenticated remote attacker can reach privileged functionality and execute code on the appliance.
The vulnerability carries a CVSS score of 9.8. It affects BIG-IP APM 17.1.0 through 17.1.3, 17.5.0 through 17.5.1 and 21.1.0 when an access policy and an OAuth profile are configured on a virtual server.
That configuration detail matters. This is not a reason to assume every BIG-IP system is exposed. It is a reason to identify the exact virtual servers that combine access policy enforcement with OAuth, then treat internet-facing matches as potential incident-response cases rather than ordinary patch tickets.
Patch only after preserving what the attacker may have left
CERT-EU recommends preserving forensic evidence, applying the relevant hotfix and conducting a compromise assessment. That order is important. An appliance reboot, rushed cleanup or incomplete log collection can remove the evidence needed to establish whether exploitation preceded remediation.
F5’s published detection guidance centres on a sequence rather than a single unmistakable indicator: repeated OAuth authentication failures, suspicious commands in the audit trail and a TMM process failure or core file close together in time.
- Review
/var/log/apmfor repeated invalid-token failures, particularly bursts of ten or more from one source address. - Use
tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failedto look for an unexplained rise in failed OAuth requests. - Correlate those events with suspicious commands in
/var/log/audit. - Investigate unexpected TMM SIGABRT events, loops and core files. A core file alone is not proof of exploitation.
- Preserve relevant logs, core files, configuration and timestamps before remediation where operationally possible.
If patching cannot happen immediately, F5 can provide an iRule-based mitigation through its support channel. That is a bridge, not a substitute for the hotfix and compromise assessment.
The gateway problem is bigger than the vulnerability score
Access gateways sit where identity, remote access and internal applications meet. They are designed to see and control traffic that most other systems never touch. Successful code execution there can therefore create a path towards credentials, sessions, application traffic and the wider network.
BlackTree previously covered a different BIG-IP APM flaw that could support a memory-only web shell. The new issue is not a continuation of that CVE and should not be conflated with it. The recurring lesson is architectural: perimeter appliances are not just controls. They are high-value computers with privileged placement and their own incident-response requirements.
What teams should do now
- Inventory the relevant configuration. Find BIG-IP APM virtual servers with both an access policy and OAuth profile.
- Prioritise exposed systems. Internet-facing deployments deserve immediate attention, but do not ignore reachable internal management paths.
- Capture evidence first. Export logs and relevant forensic artefacts before changes erase the timeline.
- Apply the hotfix. Follow F5’s version-specific guidance and validate the resulting build.
- Hunt beyond the appliance. If exploitation is suspected, investigate credentials, sessions and systems accessible through the gateway.
- Restrict management and monitoring paths. Reduce unnecessary exposure and make appliance telemetry part of central detection.
The difference between patch management and incident response is evidence of exploitation. F5 has already supplied that evidence at the campaign level. Affected organisations now need to determine whether it also exists in their own logs.
Sources
- F5 security advisory K000162605, published 22 September 2026.
- CERT-EU Security Advisory 2026-013, published 22 September 2026.
- BlackTree CVE record for CVE-2026-94127.


