External risk intelligence

F5 BIG-IP APM Remote Code Execution via OAuth Profile

CVE advisoryKnown Exploit

CVE-2026-94127

The vulnerability affects F5 BIG-IP Access Policy Manager when acting as an OAuth Authorization Server. As an edge gateway and identity-handling component, this functionality is designed to be public-facing to manage authentication traffic at the network edge.

Remote Code Execution

F5 Big Ip Access Policy Manager

17.0.0 to 17.1.317.5.0 to 17.5.121.1.0

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in F5 BIG-IP APM when configured as an OAuth Authorization Server, potentially allowing unauthenticated attackers to achieve remote code execution. This issue impacts the data plane and requires careful assessment of its relevance to our specific deployments.

  • An attacker can execute code remotely.
  • Critical flaw affects public-facing authentication.
  • Confirm relevance and exposure for our systems.

Attack Path

How an attacker could exploit the issue

An attacker can trigger this vulnerability by sending specific malicious traffic to a BIG-IP system that has both an APM access policy and an OAuth profile configured on a virtual server. This requires the BIG-IP APM to be set up as an OAuth Authorization Server. If successful, this could allow the attacker to execute code remotely on the system.

  • No authentication needed.
  • Malicious traffic to the system.
  • Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

When BIG-IP APM is configured as an OAuth Authorization Server, specific malicious traffic could lead to remote code execution on the appliance. This is a data plane issue, meaning it affects the operational functions of the system rather than its administrative interfaces, and is only present under specific configuration conditions.

  • Asset at risk: BIG-IP system, data plane.
  • How exposure could happen: Unauthenticated malicious traffic.
  • Realistic consequence: Remote code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The BIG-IP APM product, specifically when configured as an OAuth Authorization Server, presents a critical risk. Owners of these systems, likely infrastructure or platform teams, must first identify all instances of BIG-IP APM used in this capacity. Confirming whether these instances are exposed externally and handle business-critical functions is paramount. Subsequently, collaboration with security and vendor management teams will be necessary to plan and execute risk-based remediation.

  • Platform and infrastructure teams own this.
  • Verify external reachability and business criticality.
  • Plan vendor-coordinated remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is F5 BIG-IP Access Policy Manager (APM)?

BIG-IP APM is a software module for F5 hardware and virtual appliances that functions as an identity-aware access gateway. It is commonly used to manage authentication, session management, and secure access to applications. By acting as an OAuth Authorization Server, it handles the exchange of tokens and credentials for users or systems attempting to access resources.

What is the nature of the vulnerability in CVE-2026-94127?

This flaw is classified as a heap-based buffer overflow (CWE-122). In plain terms, it means the software does not correctly manage memory when processing certain data. Because of this weakness, an attacker can send specially crafted, malicious traffic to the system, causing the application to overwrite memory and potentially execute their own code remotely without needing a password.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending malicious traffic to a virtual server where both an APM access policy and an OAuth profile are active. Importantly, the flaw only exists when the BIG-IP is specifically configured as an OAuth Authorization Server. Systems that use APM only as an OAuth Client or Resource Server, or lack these specific profiles, are not subject to this trigger.

Why does Halo Surface Signal categorize this as external?

Halo Surface Signal labels this as external because the affected functionality—acting as an OAuth Authorization Server—is inherently designed to sit at the network edge. As an identity-handling gateway that processes authentication traffic from users or services, this component is often positioned to be internet-facing, making it directly reachable to remote, unauthenticated actors.

What should I do to address CVE-2026-94127?

First, inventory your F5 BIG-IP instances to see if any are running the affected versions and acting as an OAuth Authorization Server. Once identified, prioritize these for remediation. Follow official F5 guidance to apply the necessary patches or temporary mitigations. Work with your infrastructure team to ensure these updates are deployed promptly, given the critical nature of remote code execution.

References