F5 Patches Critical BIG IP APM Vulnerability Affecting OAuth Authorization Servers

Published:

F5 has released security updates for a critical vulnerability affecting BIG IP Access Policy Manager (APM), after the company confirmed that the flaw is being exploited in targeted activity. The vulnerability, tracked as CVE 2026 94127, could allow remote code execution on affected BIG IP systems without requiring authentication under specific configurations. F5 disclosed the issue through a security advisory on September 22 and released engineering hotfixes to address the problem. The vulnerability affects systems where APM is configured as an OAuth authorization server, a role that allows the platform to issue access tokens for applications. 

According to F5, the vulnerability exists when an APM access policy and an OAuth authorization server profile are configured on the same virtual server handling OAuth traffic. In this setup, specially crafted traffic sent to the virtual server may trigger a heap based buffer overflow, potentially allowing code execution on the BIG IP system. F5 rated the issue 9.8 out of 10 under CVSS version 3.1 and 9.3 under CVSS version 4.0, highlighting its severity. Since the affected traffic reaches the virtual server itself, restricting access to the BIG IP management interface does not prevent exploitation. Systems operating in Appliance mode are also affected when they meet the vulnerable configuration requirements. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE 2026 94127 to its Known Exploited Vulnerabilities catalog on September 22, directing federal civilian agencies to apply available mitigations within the required timeframe.

F5 clarified that the vulnerability is limited to systems where APM functions as an OAuth authorization server. Systems using APM only as an OAuth client or resource server without OAuth authorization server profiles are not affected. The company identified affected versions across several BIG IP branches, including 21.1, 17.5, and 17.1 releases, and provided engineering hotfixes for each supported branch. F5 noted that versions that have reached End of Technical Support were not evaluated, meaning their security status remains unknown. The company also updated its CVE record to specify that the vulnerable condition exists only when the authorization server role is enabled. Earlier descriptions from security organizations including CISA and CERT EU referenced the broader combination of an access policy and OAuth profile on a virtual server before the clarification was added.

The disclosure follows previous security concerns involving F5 APM components, including another vulnerability that was added to CISA’s Known Exploited Vulnerabilities catalog earlier in the year. F5 has advised customers to install the applicable engineering hotfix for their BIG IP version. For organizations unable to immediately apply the update, F5 has provided an iRule based mitigation option through its support channels. CERT EU has recommended preserving forensic information before applying fixes, reviewing systems for possible indicators of compromise, and beginning incident response procedures if suspicious activity is identified. CISA has also advised organizations to apply temporary protections where necessary before installing the final vendor update.

Security teams reviewing affected environments have been advised to monitor relevant logs for unusual activity. Indicators requiring investigation may include repeated failed OAuth authentication attempts, unusual increases in failed OAuth requests, suspicious commands recorded in audit logs, and certain TMM process behaviors observed by F5 during analysis. These signs should be reviewed together with other system information to determine whether further investigation is required. F5, CISA, and CERT EU have not provided details regarding the number of affected systems, identities of threat actors, or targeted organizations. They have also not confirmed whether applying the hotfix removes access in cases where unauthorized activity may have already occurred. Organizations using BIG IP APM with OAuth authorization server functionality are encouraged to assess their configurations and prioritize available security updates to reduce potential exposure.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img