Daily Top · Vulnerabilities / Identity

CISA put F5 APM OAuth on KEV. Closing the management port does not close the virtual server.

CVE-2026-94127 is unauthenticated heap overflow when APM is an OAuth authorization server. Appliance mode is in. Federal due date is Friday.

RWP Ventures · 2026-09-23 · event 2026-09-22 · 13 min read · priority 8.9

Bottom line up front

CONFIRMED CISA added CVE-2026-94127 to the Known Exploited Vulnerabilities catalog on 22 September 2026. Catalog version 2026.09.22 (released 22 September 19:02 UTC, count 1721). It is one of four new rows since [yesterday’s Zyxel GS1900 Daily Top](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/). Federal due date is 25 September 2026. Ransomware-campaign use is Unknown. Forensic triage is Yes. CISA-ADP SSVC on the NVD record: exploitation active, automatable yes, technical impact total.

The product is F5 BIG-IP Access Policy Manager. The bug is a heap-based buffer overflow (CWE-122) in the data plane. F5’s CNA score is 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and 9.3 on CVSS 4.0. Unauthenticated remote code execution. Appliance mode is in. There is no control-plane exposure in the vendor record: locking the management GUI is not the fix.

Do not collapse three facts.

  1. Not every APM box is this CVE. F5 updated the CVE record at 00:45 UTC on 23 September to say the overflow is present only when APM is an OAuth Authorization Server. Client / Resource Server deployments without authorization-server profiles are not affected. CISA’s KEV sentence and CERT-EU’s 22 September advisory still use the broader “access policy and an OAuth profile on a virtual server.” Inventory the role, not the module checkbox.
  2. The traffic hits the virtual server. Malicious OAuth traffic goes to the VIP that issues tokens. That is why CISA’s notes put the vendor iRule on the affected virtual server first, for forensic triage, then the engineering hotfix.
  3. A prior APM KEV does not close this one. CVE-2025-53521 went on KEV in March. The 17.1.3 and 17.5.1.3 builds that closed that bug sit inside this CVE’s affected ranges. A box patched for March still needs this hotfix if it is an authorization server.

This is not a re-run of [yesterday’s Zyxel KEV](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/). Different vendor, different plane, different clock.

FactRecord
CVECVE-2026-94127
ProductF5 BIG-IP APM (OAuth Authorization Server on a virtual server)
KEV catalog2026.09.22, count 1721
Added / due22 September / 25 September 2026
Vendor advisoryK000162605; datePublic 22 September 14:00 UTC
ExploitationCONFIRMED as KEV; F5: “this vulnerability has been exploited”
Ransomware useUnknown
Named CISA actorNone
OT / process impactNone claimed

What happened

F5 published K000162605 on 22 September 2026. The CNA record (updated 23 September 00:45 UTC) is the primary technical statement:

Engineering hotfixes, as restated by CCCS AL26-022 and The Hacker News from the vendor table:

BranchAffectedFixed in
21.121.1.0 before the hotfixHotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.517.5.0 through 17.5.1 before the hotfixHotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.117.1.0 through 17.1.3 before the hotfixHotfix-BIGIP-17.1.3.5.0.41.14-ENG

F5 did not evaluate End of Technical Support trains. Unknown is not safe.

CISA’s 22 September alert names four CVEs. The JSON row for 94127 matches: vendor F5, product BIG-IP APM, CWE-122, due 25 September, ransomware Unknown, forensic triage Yes. Notes tell operators to apply the iRule “to allow for proactive forensic triage,” then install the vendor patch. That sequence is the federal instruction, not an optional extra.

CERT-EU SA 2026-013 (22 September 16:52 UTC, v1.0) and CCCS AL26-022 independently restated F5’s exploitation confirmation and the same hotfix names. CERT-EU published before F5 narrowed the CVE text to authorization-server only.

The other three KEV rows from the same catalog freeze, all due 25 September, all forensic triage Yes, all ransomware Unknown:

CVEProductWhy it is not today’s Daily Top
CVE-2026-93952Arista VeloCloud Orchestrator on-premCVSS 10.0; certificate-based Edge auth + VCO web UI; hosted already patched; 6.1 / 7.0 on-prem trains still wait for a fix
CVE-2026-93616Check Point Security Management / Log / SmartEventUnauth path traversal + script exec; vendor: handful of customers, 23 July; LivePatch Take 28/29 does not close it
CVE-2026-85102Check Point Security Gateway / Spark VPNMaterial KEV add for the [13 September Daily Top](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/); Spark-targeted attempts since 12 September per Check Point. Already assessed.

Why it matters

BIG-IP APM as an OAuth authorization server is the box that issues access tokens to applications. Unauthenticated RCE there is not “a reverse proxy bug.” It is the identity plane sitting on the data plane.

Two operational lies show up in every F5 incident:

  1. “We firewalled the management interface.” This CVE is not the GUI. The overflow is in TMM handling OAuth traffic on the virtual server. CERT-EU and F5 both say so. Closing 443 on the mgmt IP does not close the VIP.
  2. “We already patched APM this year.” March’s CVE-2025-53521 was a different access-policy RCE. The builds that closed it are still in this CVE’s affected window. Patch history is not inventory.

CISA-ADP’s SSVC triple — active, automatable, total — is why the due date is three days, not two weeks. BOD 26-04’s forensic-triage flag means the ticket is not closed when the hotfix ISO is on disk.

No public victim count. F5, CISA, CERT-EU, and CCCS do not name an actor, a campaign, or a ransomware affiliate. Internet-wide APM banners on X are not a census of authorization servers.

Who / what is affected

AssetWhat to assumeStatus
BIG-IP APM 21.1.0 / 17.5.0–17.5.1 / 17.1.0–17.1.3 with an OAuth Authorization Server profile on a virtual serverIn scope for CVE-2026-94127CONFIRMED vendor (CVE updated 23 Sep 00:45 UTC)
Same trains, APM as OAuth Client / Resource Server onlyNot this CVECONFIRMED vendor
Appliance modeStill inCONFIRMED vendor
EoTS trainsNot evaluatedUNKNOWN; do not treat as safe
BIG-IP without APM, or APM without an OAuth profile on the VIPNot this CVECONFIRMED vendor prerequisite
Hosted F5 / cloud APMNot described in the CNA record we haveUNKNOWN; ask F5
Named victimsNone publishedUNKNOWN
OT / ICS / processNot claimedNo evidence
CISA ransomware fieldUnknownCONFIRMED catalog

A virtual server that matches F5’s APM 17.1 / 17.5 / 21 configuration path — Access → Federation → OAuth Authorization Server → OAuth Profile, then that profile on an access policy attached to the VIP — is the condition to inventory. That is configuration, not a CVE PoC.

Technical context

RWP is not reproducing request bodies, heap offsets, or the iRule.

What the primary records give defenders:

ATT&CK mapping for what is stated:

Follow-on that is not claimed: a named APT, ransomware-Known, token theft as observed, or OT/process impact.

Threat / exploitation status

ClaimStatusBasis
In KEV, added 22 Sep, due 25 Sep, catalog 2026.09.22 count 1721CONFIRMEDCISA alert + JSON
Exploitation in the wildCONFIRMEDF5 advisory language; KEV criterion; CERT-EU; CCCS
Unauthenticated RCE, data plane, appliance mode inCONFIRMEDF5 CNA
OAuth Authorization Server onlyCONFIRMED as of 23 Sep 00:45 UTC CVE updateF5 CNA; KEV text still broader
iRule then hotfixCONFIRMED as CISA notes + vendor workaroundCISA JSON notes; F5 workarounds
Victim count / actorUNKNOWNNo named set in F5, CISA, CERT-EU, CCCS
Ransomware useUnknownCatalog field
Forensic triage requiredYesCatalog field
SSVC active / automatable / totalCONFIRMED as CISA-ADPNVD
OT / physical-process impactNot claimedNo evidence

High confidence on: CVE ID, KEV dates, due date, catalog version and count, CVSS 9.8/9.3, CWE-122, hotfix names, forensic-triage flag, ransomware Unknown, data-plane/appliance-mode language, authorization-server narrowing in the 23 September CVE update. Moderate confidence that internet-reachable OAuth VIPs are the dominant real-world condition (SSVC automatable + data-plane; no public census). Low confidence on CISA’s unpublished exploitation evidence, on any victim identity, and on whether the hotfix displaces an existing implant.

What defenders should do

  1. Inventory APM OAuth Authorization Server VIPs, not “every BIG-IP.” Virtual server, access policy, OAuth profile, software train, hotfix build, and whether that VIP is reachable from untrusted networks. Record internet exposure for BOD 26-04. A tmsh walk of access policies and OAuth profiles is the ticket, not a banner grab.
  1. Preserve, then iRule, then hotfix. CISA’s notes are ordered that way. Snapshot logs (/var/log/apm, /var/log/audit, TMM cores, tmctl global_oauth_stat) before you reboot onto the ENG ISO. Get the iRule from F5 Support; apply it to the affected virtual server; then install the train-matched hotfix and confirm tmsh show sys version shows the ENG build.
  1. Hunt the F5 combination, not a single log line. Ten-plus invalid-token UserInfo failures from one IP, unexplained total_failed, audit commands in that window, TMM SIGABRT shortly after. Escalate that set. Do not close “no web shell on disk.” This is TMM.
  1. Do not treat March’s APM patch as this patch. If the box is on 17.1.3 or 17.5.1.3 for CVE-2025-53521 and still serves as an authorization server, it is still in the 94127 window until the ENG hotfix.
  1. Management lockdown is hygiene, not mitigation. Restrict the GUI anyway. It does not close this CVE. CCCS still recommends it as defense-in-depth.
  1. Sequence the rest of Friday’s federal list. Same due date, same catalog freeze: [Check Point VPN CVE-2026-85102](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/) (now KEV; LivePatch Take 24 was last week’s close), Check Point management CVE-2026-93616 (sk1000171; Take 28/29 is not this bug), Arista VeloCloud CVE-2026-93952 (on-prem VCO, certificate-based Edge auth, 5.2.3.16 / 6.4.2.8; 6.1 and 7.0 still waiting). [Zyxel CVE-2026-7273](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/) is due tomorrow.

This is not an exploitation guide. Use F5’s hotfix table and the OAuth-role inventory.

RWP assessment

Score 8.9. Same-day vendor confirmation, CISA KEV, a three-day BOD 26-04 clock, unauthenticated RCE on the identity plane, and a data-plane condition that makes “we closed mgmt” a false close. That is the highest-leverage row in catalog 2026.09.22.

It outranks CVE-2026-93952 (Arista VCO, CVSS 10.0, actively exploited, hosted already patched, certificate-based Edge prerequisite, two trains still unfixed) as a daily because F5 APM as an OAuth issuer is the broader enterprise identity control plane and the vendor record is tighter on primitive, plane, and hotfix. It outranks CVE-2026-93616 (Check Point management, handful of July 23 victims, LivePatch coverage gap) for the same reason: targeted management vs. automatable data-plane RCE. It outranks the CVE-2026-85102 KEV add because that VPN pair was already [13 September’s Daily Top](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/); the new fact is the catalog row, not the bug. It outranks UTA0565’s Chrome–Windows chain (CVE-2026-85046 / 87491 / 85880) as a first-day identity-appliance story — Chromium 87491 has been on KEV since 9 September. It outranks ShinyHunters’ FBI/PeopleSoft claim (REPORTED, unconfirmed by the Bureau as of this writing). [Zyxel 7273](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/) is yesterday.

The failure mode to sand down is “APM is patched” and its twin, “OAuth is only for developers.” If the VIP still issues tokens on an unhotfixed 17.1 / 17.5 / 21.1 box, you are in CISA’s denominator. If you only grepped the management ACL, you inventoried the wrong socket.

What we are watching

Sources

Sources

  1. CISA — Adds four KEV including CVE-2026-94127
  2. CISA — KEV JSON feed catalog 2026.09.22
  3. CISA — Known Exploited Vulnerabilities Catalog
  4. CISA — BOD 26-04
  5. F5 — K000162605 BIG-IP APM CVE-2026-94127
  6. CVE — CVE-2026-94127
  7. NVD — CVE-2026-94127
  8. CERT-EU — Security Advisory 2026-013
  9. CCCS — AL26-022 F5 BIG-IP APM CVE-2026-94127
  10. The Hacker News — F5 patches critical BIG-IP APM zero-day
  11. BleepingComputer — F5 patches BIG-IP APM zero-day exploited in RCE attacks
  12. CISA — Adds one KEV CVE-2026-7273