F5 says BIG-IP APM is being used if it hands out OAuth tokens
Vulnerability Management

F5 says BIG-IP APM is being used if it hands out OAuth tokens

Mathew Potter

Security Analyst

September 23, 2026

F5 said attackers are already using a hole in BIG-IP Access Policy Manager. CVE-2026-94127 lets someone run code on the box without logging in. The condition is narrow and easy to miss: APM acting as an OAuth authorization server, the thing that hands tokens to applications. CISA put it on the exploited list yesterday. Federal clock is Friday, September 25. Closing the management interface does not help. The traffic hits the virtual server that serves OAuth.

What is in scope

F5 scored it 9.8. Heap overflow is their word. We are not going to walk the traffic. Affected trains, if APM is the authorization server: 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3, each before the engineering hotfix F5 named for that branch. Appliance mode is still in. OAuth client or resource-server only, with no authorization-server profile, is out. End-of-support builds were not evaluated. Unknown is not safe.

F5 tightened the CVE text overnight. Early CISA and CERT-EU notes sounded broader (an access policy plus any OAuth profile). F5 now says authorization server only. Check the config you actually have: Access, Federation, OAuth Authorization Server, OAuth Profile, then that profile on the virtual server. If that path exists, you are in the sentence.

March's APM KEV (CVE-2025-53521) is a trap. The 17.1.3 and 17.5.1.3 builds that closed that one sit inside today's affected ranges. A box that "already patched APM" still needs this hotfix if it issues tokens.

What F5 told people to look for

CERT-EU repeated F5's hunt list. The combination that should wake someone up is repeated OAuth failures, then odd commands, then a TMM abort shortly after. Failed UserInfo lines in the APM log that say the access token is invalid, especially ten or more from one address. An unexplained climb in total_failed on the OAuth counters. Suspicious commands in the audit log in that same window. TMM core files are not proof on their own. F5 has not said the hotfix kicks out someone who is already in. Preserve first if you think you were hit, then patch, then look again.

Why this is a Canadian shop problem

BIG-IP in front of a staff portal or a partner app is common in mid-size Alberta. OAuth on that box is how mobile apps and SaaS get tokens without another VPN. The person who locked down the management VLAN did the right thing last year and is still open this week. VeloCloud yesterday was the SD-WAN map. This is the login broker. Same class of device: one box, many doors.

What we would do before Friday

  • Name every BIG-IP that has APM. If it issues OAuth tokens, you want F5's engineering hotfix for that train. If you cannot install it today, open a ticket and ask for their iRule. CISA told agencies to put the iRule on first so they can look, then install the final fix.
  • Do not treat a closed management port as the mitigation. It is not.
  • Hunt the vendor signs. If you get the failure-then-commands-then-abort pattern, preserve logs and call it an incident, not a reboot.
  • Zyxel GS1900 is due tomorrow. Do not let Friday's F5 clock bury Thursday's switch.

Bottom line

The box that hands out tokens is a computer on the internet. Forensic Five will ask whether APM is an authorization server and which hotfix is on it. From St. Albert, Alberta. Install the engineering build. Then go look at the cPanel and the WordPress versions, because those two do not need a BIG-IP to matter.

Tags

F5 BIG-IP CVE-2026-94127 OAuth CISA KEV

Share This Article

About the Author

Mathew Potter

Security Analyst

Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.