Mathew Potter
Security Analyst
F5 said attackers are already using a hole in BIG-IP Access Policy Manager. CVE-2026-94127 lets someone run code on the box without logging in. The condition is narrow and easy to miss: APM acting as an OAuth authorization server, the thing that hands tokens to applications. CISA put it on the exploited list yesterday. Federal clock is Friday, September 25. Closing the management interface does not help. The traffic hits the virtual server that serves OAuth.
F5 scored it 9.8. Heap overflow is their word. We are not going to walk the traffic. Affected trains, if APM is the authorization server: 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3, each before the engineering hotfix F5 named for that branch. Appliance mode is still in. OAuth client or resource-server only, with no authorization-server profile, is out. End-of-support builds were not evaluated. Unknown is not safe.
F5 tightened the CVE text overnight. Early CISA and CERT-EU notes sounded broader (an access policy plus any OAuth profile). F5 now says authorization server only. Check the config you actually have: Access, Federation, OAuth Authorization Server, OAuth Profile, then that profile on the virtual server. If that path exists, you are in the sentence.
March's APM KEV (CVE-2025-53521) is a trap. The 17.1.3 and 17.5.1.3 builds that closed that one sit inside today's affected ranges. A box that "already patched APM" still needs this hotfix if it issues tokens.
CERT-EU repeated F5's hunt list. The combination that should wake someone up is repeated OAuth failures, then odd commands, then a TMM abort shortly after. Failed UserInfo lines in the APM log that say the access token is invalid, especially ten or more from one address. An unexplained climb in total_failed on the OAuth counters. Suspicious commands in the audit log in that same window. TMM core files are not proof on their own. F5 has not said the hotfix kicks out someone who is already in. Preserve first if you think you were hit, then patch, then look again.
BIG-IP in front of a staff portal or a partner app is common in mid-size Alberta. OAuth on that box is how mobile apps and SaaS get tokens without another VPN. The person who locked down the management VLAN did the right thing last year and is still open this week. VeloCloud yesterday was the SD-WAN map. This is the login broker. Same class of device: one box, many doors.
The box that hands out tokens is a computer on the internet. Forensic Five will ask whether APM is an authorization server and which hotfix is on it. From St. Albert, Alberta. Install the engineering build. Then go look at the cPanel and the WordPress versions, because those two do not need a BIG-IP to matter.
Security Analyst
Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.