Skip to main content

F5 BIG-IP APM OAuth Remote Code Execution Remains a Priority Past Its Federal Deadline (CVE-2026-94127)

Scope: F5 BIG-IP Systems Where APM Is Configured as an OAuth Authorization Server on the Same Virtual Server Receiving OAuth Traffic

Severity: Red

CVE-2026-94127, a critical heap-based buffer overflow in F5 BIG-IP Access Policy Manager rated 9.8 on CVSS v3.1, was added to CISA's Known Exploited Vulnerabilities catalog on September 22, 2026 with a federal remediation deadline of September 25, 2026, which has now passed. The vulnerability only affects virtual servers configured with both an APM access policy and an OAuth authorization server profile, a setup organizations use when BIG-IP issues OAuth access tokens to connected applications, and unauthenticated attackers can send specially crafted traffic directly to that virtual server to achieve remote code execution. Because the malicious traffic targets the virtual server itself rather than the administrative management interface, restricting access to BIG-IP's management console provides no protection against this specific flaw, a detail that has reportedly led some organizations to mistakenly believe they were already covered by existing network segmentation. Systems using APM only as an OAuth client or resource server, without an authorization server profile, are not affected. Organizations that have not yet applied F5's engineering hotfix must do so immediately, and should review /var/log/audit for suspicious commands occurring around any repeated OAuth authentication failures as a sign of possible prior compromise.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.