A heap overflow in BIG-IP APM lets outsiders run code

A heap overflow in BIG-IP APM hands unauthenticated attackers code execution on any appliance serving as an OAuth authorization server.

CSBadmin
2 Min Read

Attackers are exploiting CVE-2026-94127, a heap-based buffer overflow in F5 BIG-IP Access Policy Manager that lets unauthenticated traffic run code on the appliance.

The catch is configuration. Only deployments where APM serves as an OAuth authorization server are exposed, which means an APM access policy and an OAuth authorization server profile share one virtual server. Systems using APM purely as an OAuth client or resource server are unaffected. F5 scored the bug 9.8 under CVSS v3.1 and 9.3 under v4.0.

Do not expect a management-interface lockdown to help. The exploit traffic goes straight to the virtual server that answers OAuth requests, so any control applied to BIG-IP administration does nothing against it. Appliance mode offers no cover either.

Engineering hotfixes exist for the 21.1, 17.5 and 17.1 branches. Where patching is not immediate, F5 supplies an iRule mitigation through a support ticket. CISA told agencies to apply that first so they could triage forensically, then install the final fix. Versions past end of technical support were never assessed, so their status is unknown rather than safe.

Hunting guidance points to repeated failed UserInfo requests in /var/log/apm reporting “The access token is invalid”, especially 10 or more from a single IP in a short window; a rising total_failed count from tmctl global_oauth_stat; suspicious commands in /var/log/audit; and TMM core files that follow. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 22 with a September 25 deadline for federal agencies. Teams that patched for CVE-2025-53521 back in March are still exposed here.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.