CVE-2026-94127: BIG-IP APM OAuth vulnerability

Published Sep 22, 2026
·
Updated

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

Other sources

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.

Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

NVD

When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).

Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

MITRE

Affected Software

2 affected components
F5 BIG-IP APM
F5 BIG-IP APM

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Discontinue use of the F5 BIG-IP APM product if mitigations are unavailable.

Event History

Sep 22, 2026
CVE Published
via CISA·12:00 AM
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

A virtual server is affected when it has both a BIG-IP APM access policy and an OAuth profile configured. BIG-IP systems running in Appliance mode are also vulnerable.

2

Does exploitation require credentials or user interaction?

No. An unauthenticated attacker can exploit the issue using specific malicious traffic, with no privileges or user interaction indicated.

3

Is the management or control plane exposed?

No. This is a data plane issue, and the provided information states that there is no control plane exposure.

4

What does the assessment say about versions that have reached End of Technical Support?

Versions that have reached End of Technical Support were not evaluated. Their exposure status cannot be determined from the provided assessment.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203