CTIPilot

F5 BIG-IP Access Policy Manager (APM)

product · product:f5-big-ip-access-policy-manager-apm

Coverage timeline
1
first 2026-09-23 → last 2026-09-23
Peak priority
critical
1 critical
Sources cited
5
5 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

Releases covered
F5 BIG-IP Access Policy Manager (APM)
ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-23/cve-2026-94127-f5-big-ip-apm-oauth-heap-overflow-rce · ATT&CK page ↗

Story timeline

  1. 2026-09-23CVE-2026-94127, F5 BIG-IP APM: unauthenticated heap overflow in OAuth-profile processing reaches RCE on the TMM data plane (CVSS 9.8)
    trending-vulnerabilitiesF5 confirms exploitation of an unauthenticated RCE in BIG-IP's OAuth authentication gateway

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • advisories.ncsc.nl1 (20%)
  • cert.europa.eu1 (20%)
  • cisa.gov1 (20%)
  • fieldeffect.com1 (20%)
  • securityonline.info1 (20%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about F5 BIG-IP Access Policy Manager (APM) (1)

2026-09-23 · view entry permalink →

CRITICALCVE-2026-94127exploitedNATOA1

CVE-2026-94127, F5 BIG-IP APM: unauthenticated heap overflow in OAuth-profile processing reaches RCE on the TMM data plane (CVSS 9.8)

CVE-2026-94127 (CVSS 3.1: 9.8, CVSS 4.0: 9.3, CWE-122 heap-based buffer overflow) is a vulnerability in F5 BIG-IP Access Policy Manager (APM) reachable on the Traffic Management Microkernel (TMM) data plane; F5 states "this is a data plane issue; there is no control plane exposure" (F5, via SecurityOnline, 2026-09-22). It triggers only on a virtual server configured with both an APM access policy and an OAuth profile. "When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE)" (F5, via SecurityOnline / Daily CyberSecurity, 2026-09-22): the OAuth-profile request-handling logic writes attacker-influenced data into a heap allocation without validating its size, corrupting adjacent heap memory and ultimately hijacking control flow inside TMM, exploitable by an unauthenticated, network-only attacker with no user interaction. Affected: BIG-IP APM 21.1.0, 17.5.0–17.5.1, and 17.1.0–17.1.3. Fixed via engineering hotfixes (Hotfix-BIGIP-21.1.0.2.0.30.22, Hotfix-BIGIP-17.5.1.9.0.160.12, Hotfix-BIGIP-17.1.3.5.0.41.14); F5 also offers an emergency iRule mitigation through F5 Support for organizations that cannot immediately apply the hotfix. "The vendor confirmed active exploitation in the wild" (CERT-EU, Security Advisory 2026-013, 2026-09-22); CISA added it to KEV the same day (CISA KEV, catalogue version 2026.09.22) with a 2026-09-25 remediation deadline.

Detection concept, directly from the vendor's own compromise-assessment guidance (vendor-neutral telemetry classes): repeated OAuth "UserInfo" request failures with an "invalid_token" error code from a single source in a short window (F5's own threshold is 10 or more occurrences) in the APM authentication log; an unexplained rise in the failed-OAuth-request counter relative to total OAuth requests, queryable via the platform's internal OAuth statistics; administrative-audit-log review around the same timestamps as any OAuth failure spike, correlated with a TMM process crash or core file caused by the microkernel entering an abort loop. F5's own framing: "at a high level, multiple OAuth authentication failures, followed by suspicious commands, shortly followed by a TMM SIGABRT is the combination that should lead to human review of the system" (CERT-EU, Security Advisory 2026-013, 2026-09-22); no single signal is by itself an indicator of compromise. Triage: an isolated OAuth authentication failure or an occasional TMM restart happens in normal operation; the correlated sequence (failure spike, then suspicious commands, then a TMM crash) is the discriminator. Hardening: inventory every virtual server pairing an APM access policy with an OAuth profile, since the exposure is entirely configuration-gated; apply the engineering hotfix or the emergency iRule; internet-facing instances of this authentication-gateway component are the highest remediation priority.

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE).

This is a data plane issue; there is no control plane exposure.

SecurityOnline / Daily CyberSecurity 2026-09-22

The vendor confirmed active exploitation in the wild

At a high level, multiple OAuth authentication failures, followed by suspicious commands, shortly followed by a TMM SIGABRT is the combination that should lead to human review of the system.

CERT-EU (Security Advisory 2026-013) 2026-09-22
vulnerability23 Sep 04:42Zmulti-sourceOpen finding ↗