Organizations using certain F5 BIG-IP Access Policy Manager configurations face an urgent patching and investigation task after the disclosure of an actively exploited remote-code-execution vulnerability. The flaw, tracked as CVE-2026-94127, carries a CVSS v3.1 score of 9.8.
A Narrow Configuration With Serious Consequences
The vulnerability affects BIG-IP APM installations acting as OAuth authorization servers. The dangerous configuration combines an APM access policy with an OAuth authorization-server profile on the same virtual server. Specially constructed network traffic sent to that service can trigger a heap-based buffer overflow and allow code execution without authentication.
Systems operating only as OAuth clients or resource servers are not affected, according to the updated scope published by F5. However, organizations should verify the actual configuration rather than assuming that OAuth functionality is unused or limited to a safer role.
A particularly important detail is that the malicious traffic reaches the application-facing virtual server. Restricting access to the BIG-IP management interface therefore does not prevent exploitation. Appliance-mode deployments can also be vulnerable.
Hotfixes and Forensic Review
F5 has released engineering hotfixes for supported branches and offers an iRule mitigation to customers who cannot install the correction immediately. End-of-support versions were not evaluated, leaving their security status uncertain.
Administrators should preserve relevant evidence before making changes, then install the appropriate hotfix and inspect the appliance for suspicious activity. Potential warning signs include repeated failed OAuth UserInfo requests, unexplained increases in failed OAuth counters, unusual commands in audit logs and TMM process crashes occurring near suspicious authentication activity.
Recommended Response
- Identify every APM virtual server using an OAuth authorization-server profile.
- Apply the branch-specific engineering hotfix or obtain the temporary iRule.
- Retain APM, audit and system logs before remediation.
- Investigate suspicious commands and authentication failures.
- Rotate exposed credentials if compromise cannot be excluded.
In my view, patching alone is not sufficient when exploitation has already been confirmed. An attacker who obtained execution may have established another access path that survives the update. Affected appliances should be treated as potentially compromised security infrastructure and subjected to a disciplined incident-response process.
