F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
A critical zero-day vulnerability (CVE-2026-94127) in F5 BIG-IP APM allows unauthenticated remote code execution when APM is configured as an OAuth authorization server. The vulnerability is being actively exploited, and CISA has urged federal agencies to apply F5's hotfix immediately. Affected systems require a specific configuration where APM serves as an OAuth authorization server alongside an access policy and OAuth profile on the same virtual server.
A critical zero-day vulnerability (CVE-2026-94127) in F5 BIG-IP Access Policy Manager (APM) is being exploited to allow unauthenticated remote code execution. The flaw stems from a heap-based buffer overflow that occurs when APM is configured as an OAuth authorization server, issuing access tokens to applications. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on September 22, urging federal civilian agencies to apply F5's engineering hotfixes by September 25, under a directive issued in June.
Specifically, the vulnerability is present only when APM acts as an OAuth authorization server, alongside an access policy and an OAuth profile on the same virtual server. F5’s CVE record and CISA’s KEV entry do not specify the number of systems impacted or the attackers involved.
Affected versions include those running APM 17.1, 17.5 and 21.0. Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected. F5 has released an engineering hotfix to address the issue, and offers an iRule mitigation for virtual servers where the hotfix cannot be immediately applied, obtainable through a support ticket. CERT-EU advises preserving forensic evidence, applying the hotfix, checking for signs of compromise, and initiating incident response if any are detected.
CISA recommends applying the iRule first to allow for proactive forensic triage, followed by installing the final vendor patch as soon as possible. Signs of compromise include repeated failed UserInfo requests in /var/log/apm with the error description "The access token is invalid," a rise in total_failed in OAuth counter, suspicious commands in /var/log/audit around those failures, and TMM core files showing a loop causing the SOD daemon to send a SIGABRT. F5’s CVE record and the CISA and CERT-EU advisories do not indicate whether applying the hotfix removes access already gained by an attacker.
