Pandorex
Security

F5 BIG-IP APM: Exploited OAuth RCE Hits Specific Configurations

Published Pandorex Redaktion·2 min read
—
Illustration: a red attack path crosses an edge gateway's OAuth key and damages its data plane while a shield and warning log respond.
Editorial illustration · Pandorex

In brief: F5 confirms active attacks against CVE-2026-94127 in BIG-IP Access Policy Manager. The heap-based buffer overflow enables unauthenticated code execution, but not every APM deployment is exposed. A specific OAuth authorisation-server configuration on a virtual server is required.

Confirmed: RCE in the data plane

A virtual server is vulnerable when it combines an APM access policy with an OAuth profile and APM acts as an OAuth Authorization Server. Crafted network traffic can corrupt memory and execute code on the BIG-IP system. Deployments using APM only as an OAuth Client or Resource Server, without an authorisation-server profile, are not affected according to F5.

F5 lists BIG-IP APM 17.1.0 through 17.1.3, 17.5.0 through 17.5.1 and 21.1.0. Versions beyond technical support were not evaluated. CVE-2026-94127 scores 9.8 under CVSS 3.1 and 9.3 under CVSS 4.0. Appliance Mode does not protect the device. F5 classifies this as a data-plane issue; direct exposure of the management plane is unnecessary.

Engineering hotfixes are available for supported branches. Customers unable to patch immediately can obtain an iRule-based temporary mitigation from F5 Support. CERT-EU advises preserving forensic evidence before making changes, then applying the hotfix and checking for compromise.

Pandorex Analysis: version scanners are insufficient

The configuration dependency cuts both ways. A version-only inventory may flag too many systems, while an isolated management interface can create false confidence because attackers target the reachable data-plane virtual server. Internet-facing APM systems that issue OAuth tokens as authorisation servers deserve priority.

F5's traces should be assessed as a sequence: repeated OAuth invalid_token failures in /var/log/apm, an unexplained rise in total_failed, suspicious commands in /var/log/audit, then a TMM abort with SIGABRT. A TMM core alone does not prove exploitation. CERT-EU treats ten or more token failures from one IP in a short period as a reason for manual review.

Because exploitation preceded the public fix, “patched now” is not a complete response. Operators must investigate the pre-hotfix window and start incident response when evidence appears. NHS England's National CSOC explicitly assesses further exploitation as highly likely.

Sources and references

Sources used for the facts and context in this article.

  1. F5, 22.09.2026: K000162605 — BIG-IP APM vulnerability CVE-2026-94127my.f5.com
  2. CVE Program, 22.09.2026: CVE-2026-94127cve.org
  3. CERT-EU, 22.09.2026: Security Advisory 2026-013cert.europa.eu
  4. NHS England Digital, 23.09.2026: Critical RCE Vulnerability in F5 BIG-IP APM Under Exploitationdigital.nhs.uk

How Pandorex researches and corrects articles

Comments

Sign in to write a comment.

Swipe up
Next Article

Palo Alto Turns AI Red Teaming Into a Continuous Service

Security