---
schema: 1
kind: vulnerability
title: "CVE-2026-94127 — F5 BIG-IP APM: unauthenticated heap overflow in OAuth-profile processing reaches RCE on the TMM data plane (CVSS 9.8)"
headline: "F5 confirms exploitation of an unauthenticated RCE in BIG-IP's OAuth authentication gateway"
summary: >
  An unauthenticated, network-only attacker can trigger a heap-based buffer
  overflow in F5 BIG-IP Access Policy Manager's OAuth-profile handling,
  reaching remote code execution on the TMM data plane. F5 confirms active
  exploitation; the exposure is limited to virtual servers configured with
  both an APM access policy and an OAuth profile.
discovered_at: "2026-09-23T04:42:00Z"
updated_at: null
event_date: "2026-09-22"
run_id: 2026-09-23T0405Z-intel
priority: critical
immediate_action:
  title: "Patch or apply the emergency iRule to every BIG-IP APM virtual server pairing an access policy with an OAuth profile"
  action: >
    F5 confirms active exploitation of this unauthenticated RCE. Inventory
    every virtual server that combines an APM access policy with an OAuth
    profile. Apply the
    engineering hotfix now (21.1.0.2.0.30.22 / 17.5.1.9.0.160.12 /
    17.1.3.5.0.41.14); where the hotfix cannot land immediately, request the
    emergency iRule mitigation from F5 Support. Prioritise internet-facing
    instances.
tags: [vulnerabilities, rce, pre-auth, actively-exploited, cisa-kev, identity]
regions: [global]
sectors: [public-sector]
entities: ["product:f5-big-ip-access-policy-manager-apm"]
techniques: [T1190]
affected_products: ["F5 BIG-IP Access Policy Manager (APM)"]
cves:
  - id: CVE-2026-94127
    cvss: "9.8 (CVSS3.1) / 9.3 (CVSS4.0)"
    epss: null
    type: memory-corruption
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "BIG-IP APM 21.1.0; 17.5.0–17.5.1; 17.1.0–17.1.3 (virtual server with an APM access policy AND an OAuth profile configured)"
    fixed: "Hotfix-BIGIP-21.1.0.2.0.30.22; Hotfix-BIGIP-17.5.1.9.0.160.12; Hotfix-BIGIP-17.1.3.5.0.41.14; emergency iRule mitigation available via F5 Support"
sources:
  - url: "https://cert.europa.eu/publications/security-advisories/2026-013/"
    publisher: "CERT-EU (Security Advisory 2026-013)"
    date: "2026-09-22"
    role: primary
  - url: "https://fieldeffect.com/blog/f5-fixes-big-ip-apm-vulnerability"
    publisher: "Field Effect"
    date: "2026-09-22"
    role: corroborating
  - url: "https://securityonline.info/big-ip-apm-vulnerability-cve-2026-94127/"
    publisher: "SecurityOnline / Daily CyberSecurity"
    date: "2026-09-22"
    role: corroborating
  - url: "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0386"
    publisher: "NCSC-NL (NCSC-2026-0386)"
    date: "2026-09-22"
    role: corroborating
closed_sources: []
evidence:
  - quote: "When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE)."
    publisher: "SecurityOnline / Daily CyberSecurity"
    source_url: "https://securityonline.info/big-ip-apm-vulnerability-cve-2026-94127/"
  - quote: "This is a data plane issue; there is no control plane exposure."
    publisher: "SecurityOnline / Daily CyberSecurity"
    source_url: "https://securityonline.info/big-ip-apm-vulnerability-cve-2026-94127/"
  - quote: "The vendor confirmed active exploitation in the wild"
    publisher: "CERT-EU (Security Advisory 2026-013)"
    source_url: "https://cert.europa.eu/publications/security-advisories/2026-013/"
  - quote: "At a high level, multiple OAuth authentication failures, followed by suspicious commands, shortly followed by a TMM SIGABRT is the combination that should lead to human review of the system."
    publisher: "CERT-EU (Security Advisory 2026-013)"
    source_url: "https://cert.europa.eu/publications/security-advisories/2026-013/"
verification: multi-source
sourcing_note: "F5's own advisory (my.f5.com K000162605) is a client-rendered SPA that returned only a loading shell on direct fetch and via the jina reader; relayed here via CERT-EU's advisory, which quotes F5's text directly, corroborated by two independent write-ups quoting the same language."
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - "Inventory every BIG-IP APM virtual server pairing an access policy with an OAuth profile, and patch or apply the emergency iRule to each one now."
updates: []
migrated_from: null
---

CVE-2026-94127 (CVSS 3.1: 9.8, CVSS 4.0: 9.3, CWE-122 heap-based buffer overflow) is a vulnerability in F5 BIG-IP Access Policy Manager (APM) reachable on the Traffic Management Microkernel (TMM) data plane — F5 states "this is a data plane issue; there is no control plane exposure" ([F5, via SecurityOnline, 2026-09-22](https://securityonline.info/big-ip-apm-vulnerability-cve-2026-94127/)). It triggers only on a virtual server configured with both an APM access policy and an OAuth profile. "When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE)" ([F5, via SecurityOnline / Daily CyberSecurity, 2026-09-22](https://securityonline.info/big-ip-apm-vulnerability-cve-2026-94127/)): the OAuth-profile request-handling logic writes attacker-influenced data into a heap allocation without validating its size, corrupting adjacent heap memory and ultimately hijacking control flow inside TMM — exploitable by an unauthenticated, network-only attacker with no user interaction. Affected: BIG-IP APM 21.1.0, 17.5.0–17.5.1, and 17.1.0–17.1.3. Fixed via engineering hotfixes (Hotfix-BIGIP-21.1.0.2.0.30.22, Hotfix-BIGIP-17.5.1.9.0.160.12, Hotfix-BIGIP-17.1.3.5.0.41.14); F5 also offers an emergency iRule mitigation through F5 Support for organizations that cannot immediately apply the hotfix. "The vendor confirmed active exploitation in the wild" ([CERT-EU, Security Advisory 2026-013, 2026-09-22](https://cert.europa.eu/publications/security-advisories/2026-013/)); CISA added it to KEV the same day ([CISA KEV, catalogue version 2026.09.22](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)) with a 2026-09-25 remediation deadline.

Detection concept, directly from the vendor's own compromise-assessment guidance (vendor-neutral telemetry classes): repeated OAuth "UserInfo" request failures with an "invalid_token" error code from a single source in a short window (F5's own threshold is 10 or more occurrences) in the APM authentication log; an unexplained rise in the failed-OAuth-request counter relative to total OAuth requests, queryable via the platform's internal OAuth statistics; administrative-audit-log review around the same timestamps as any OAuth failure spike, correlated with a TMM process crash or core file caused by the microkernel entering an abort loop. F5's own framing: "at a high level, multiple OAuth authentication failures, followed by suspicious commands, shortly followed by a TMM SIGABRT is the combination that should lead to human review of the system" ([CERT-EU, Security Advisory 2026-013, 2026-09-22](https://cert.europa.eu/publications/security-advisories/2026-013/)) — no single signal is by itself an indicator of compromise. **Triage:** an isolated OAuth authentication failure or an occasional TMM restart happens in normal operation; the correlated sequence — failure spike, then suspicious commands, then a TMM crash — is the discriminator. Hardening: inventory every virtual server pairing an APM access policy with an OAuth profile, since the exposure is entirely configuration-gated; apply the engineering hotfix or the emergency iRule; internet-facing instances of this authentication-gateway component are the highest remediation priority.

**Defender takeaway:** an APM+OAuth virtual server that has not applied the hotfix or the iRule mitigation is exposed to unauthenticated RCE right now — the configuration-gated exposure means a targeted inventory check, not a blanket assumption, decides which servers need immediate action.
