F5 BIG-IP APM Unauthenticated Remote Code Execution Actively Exploited on OAuth-Configured Systems (CVE-2026-94127)
Scope: F5 BIG-IP Access Policy Manager, Virtual Servers Configured with Both an APM Access Policy and an OAuth Authorization Server Profile
Severity: Red
F5 disclosed and patched CVE-2026-94127 on September 22, 2026, a critical heap-based buffer overflow in BIG-IP APM rated CVSS 9.8, and confirmed the flaw is being actively exploited in the wild. The vulnerability exists specifically where a virtual server has both an APM access policy and an OAuth profile configured, with APM acting as an OAuth authorization server, a setup organizations commonly use when BIG-IP serves as the authentication gateway for applications relying on OAuth, single sign-on, or federated identity. Specially crafted traffic sent to that virtual server can corrupt memory and lead to unauthenticated remote code execution, and because the malicious traffic targets the virtual server directly rather than a management interface, restricting access to BIG-IP's administrative console provides no protection against this specific flaw. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog the same day, with a federal remediation deadline of September 25, 2026, and specifically requires forensic triage in addition to patching, given that exploitation was already underway before most customers were aware of the flaw. Organizations must apply F5's temporary iRule mitigation first to enable forensic triage of potentially compromised systems, then install the engineering hotfix appropriate to their BIG-IP branch, and review logs for the vendor's documented indicators, including repeated OAuth authentication failures followed by suspicious commands and a Traffic Management Microkernel crash.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.