F5 Addresses Critical Vulnerability in BIG-IP APM: Immediate Action Required
On Tuesday, F5 Networks, a prominent technology company, took decisive action to address a critical vulnerability within its BIG-IP Access Policy Manager (APM) platform. The security flaw, identified as CVE-2026-94127, poses a serious risk as it allows for remote code execution (RCE) and affects configurations set up as OAuth authorization servers. Alarmingly, this vulnerability was already in active exploitation in the wild before the patch went live.
The BIG-IP APM serves as a vital component of F5’s BIG-IP hardware platform, enabling organizations to manage access to internal network resources effectively. Its capabilities encompass a range of functions, including client-side checks, authentication, authorization, and the facilitation of VPN connectivity for remote users. Nonetheless, the newly identified flaw could have significant implications for any organization relying on this setup.
This vulnerability is characterized as a heap-based buffer overflow and carries a concerning rating of 9.8 on the Common Vulnerability Scoring System (CVSS) scale. The exploitation potential is particularly pronounced when the BIG-IP system operates in appliance mode, contingent upon both the APM configuration and the OAuth authorization server settings being correctly applied. Deployments that utilize APM solely as an OAuth client or resource server remain unaffected, as per the company’s advisory.
F5 has strongly recommended that users take immediate steps to secure their installations by applying the necessary hotfixes. The hotfix for the 21.x release branch is labeled Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso, while users on the 17.5.x and 17.1.x branches should implement Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso or Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso, respectively.
In its continuous commitment to security, F5 has also developed an iRule, which customers can access through the support portal. This iRule serves as a temporary mitigation measure to deploy until the official patch can be applied.
The urgency of the situation has not gone unnoticed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), which incorporated this vulnerability into its Known Exploited Vulnerabilities (KEV) catalog on the same day, underscoring the confirmed active exploitation in the digital landscape. Further compounding this concern, the Shadowserver Foundation reported tracking over 15,000 exposed BIG-IP APM deployments across the globe. Notably, approximately 5,000 of these vulnerable systems are situated in North America and Europe.
F5 has articulated the need for users to proactively monitor their systems for any signs of compromise. Specifically, the presence of multiple OAuth authentication failures could serve as an early warning sign. The company emphasizes that the occurrence of merely one failure is not enough to indicate exploitation, but multiple failures—particularly those exceeding ten messages in the logs from a singular IP address—are grounds for deeper investigation.
To aid administrators in this effort, F5 has provided command-line tools to facilitate monitoring. For instance, executing the command tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed will yield a summary of authentication failures. Should there be indications of suspicious activity—specifically related to OAuth messages—system administrators are advised to peruse the log entries around those timestamps in the /var/log/audit directory. Additionally, the presence of TMM core files warrants scrutiny, as exploitation could cause the Traffic Management Microkernel (TMM) to terminate unexpectedly and generate such files.
Over recent years, F5’s BIG-IP APM and similar devices have increasingly attracted the attention of cybercriminals. Attackers have targeted these network edge devices and VPN gateways to penetrate corporate networks. Just this month, cybersecurity researchers unveiled a Linux rootkit designed explicitly for BIG-IP APM systems, linked to the exploitation of an older vulnerability, CVE-2025-5352.
As organizations strive to bolster their cybersecurity measures in response to evolving threats, the onus is on users of F5 technologies to promptly address this vulnerability, applying necessary patches and monitoring for signs of compromise diligently. The escalating sophistication of cyberattacks underscores the importance of vigilance within the realm of cybersecurity, particularly for systems that serve as critical gateways to internal networks.
