→ Back to Home
Application Security

Critical F5 BIG-IP APM Zero-Day Enables Unauthenticated RCE via OAuth Profiles

F5 released emergency engineering hotfixes addressing CVE-2026-94127, a maximum-severity heap buffer overflow vulnerability affecting BIG-IP Access Policy Manager (APM) instances configured as OAuth authorization servers. Disclosed following active exploitation in the wild, the vulnerability carries a CVSS v3.1 score of 9.8 (and CVSS v4.0 score of 9.3) and allows unauthenticated threat actors to achieve remote code execution by sending specially crafted network traffic directly to the virtual server endpoint. This incident is particularly dangerous for enterprise architectures because the attack vector bypasses standard perimeter hardening. Typically, security teams isolate management interfaces and rely on the gateway to secure internal applications. In this scenario, the vulnerability lives on the same virtual server that processes public or ingress OAuth authentication traffic. Appliance-mode deployments are also susceptible, rendering standard access control lists on management ports ineffective. This flaw reflects a growing trend where identity providers, reverse proxies, and authentication gateways are heavily targeted by advanced threat actors. As organizations consolidate edge security and OAuth token minting into centralized appliances, these edge systems become high-value single points of failure. When an authorization server itself is susceptible to memory corruption, attackers can subvert identity boundaries before application logic even executes. Security engineers and platform operators must immediately audit all BIG-IP deployments to determine whether APM is actively serving the OAuth authorization server role. Affected branches—including 17.1, 17.5, and 21.1—require immediate deployment of vendor-provided engineering hotfixes. If immediate hotfix application is impossible, teams must evaluate temporary traffic-filtering rules or isolate affected virtual servers from untrusted networks while monitoring closely for anomalous heap corruption crashes or unexpected outbound connections from gateway appliances.
#application security#vulnerability#f5 big-ip#oauth#zero-day
Read original source