CISA put F5 APM OAuth on KEV. Closing the management port does not close the virtual server.
CVE-2026-94127 is unauthenticated heap overflow when APM is an OAuth authorization server. Appliance mode is in. Federal due date is Friday.
Bottom line up front
CONFIRMED CISA added CVE-2026-94127 to the Known Exploited Vulnerabilities catalog on 22 September 2026. Catalog version 2026.09.22 (released 22 September 19:02 UTC, count 1721). It is one of four new rows since [yesterday’s Zyxel GS1900 Daily Top](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/). Federal due date is 25 September 2026. Ransomware-campaign use is Unknown. Forensic triage is Yes. CISA-ADP SSVC on the NVD record: exploitation active, automatable yes, technical impact total.
The product is F5 BIG-IP Access Policy Manager. The bug is a heap-based buffer overflow (CWE-122) in the data plane. F5’s CNA score is 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and 9.3 on CVSS 4.0. Unauthenticated remote code execution. Appliance mode is in. There is no control-plane exposure in the vendor record: locking the management GUI is not the fix.
Do not collapse three facts.
- Not every APM box is this CVE. F5 updated the CVE record at 00:45 UTC on 23 September to say the overflow is present only when APM is an OAuth Authorization Server. Client / Resource Server deployments without authorization-server profiles are not affected. CISA’s KEV sentence and CERT-EU’s 22 September advisory still use the broader “access policy and an OAuth profile on a virtual server.” Inventory the role, not the module checkbox.
- The traffic hits the virtual server. Malicious OAuth traffic goes to the VIP that issues tokens. That is why CISA’s notes put the vendor iRule on the affected virtual server first, for forensic triage, then the engineering hotfix.
- A prior APM KEV does not close this one. CVE-2025-53521 went on KEV in March. The 17.1.3 and 17.5.1.3 builds that closed that bug sit inside this CVE’s affected ranges. A box patched for March still needs this hotfix if it is an authorization server.
This is not a re-run of [yesterday’s Zyxel KEV](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/). Different vendor, different plane, different clock.
| Fact | Record |
|---|---|
| CVE | CVE-2026-94127 |
| Product | F5 BIG-IP APM (OAuth Authorization Server on a virtual server) |
| KEV catalog | 2026.09.22, count 1721 |
| Added / due | 22 September / 25 September 2026 |
| Vendor advisory | K000162605; datePublic 22 September 14:00 UTC |
| Exploitation | CONFIRMED as KEV; F5: “this vulnerability has been exploited” |
| Ransomware use | Unknown |
| Named CISA actor | None |
| OT / process impact | None claimed |
What happened
F5 published K000162605 on 22 September 2026. The CNA record (updated 23 September 00:45 UTC) is the primary technical statement:
- Prerequisite: an APM access policy and an OAuth profile on the same virtual server, with APM acting as an OAuth Authorization Server.
- Primitive: crafted traffic → heap overflow → unauthenticated RCE.
- Plane: data plane. Control plane is not the exposure.
- Appliance mode: vulnerable.
- Finder: F5, internal discovery.
- Workaround: an iRule, available from F5 Support on request. RWP is not reprinting it.
Engineering hotfixes, as restated by CCCS AL26-022 and The Hacker News from the vendor table:
| Branch | Affected | Fixed in |
|---|---|---|
| 21.1 | 21.1.0 before the hotfix | Hotfix-BIGIP-21.1.0.2.0.30.22-ENG |
| 17.5 | 17.5.0 through 17.5.1 before the hotfix | Hotfix-BIGIP-17.5.1.9.0.160.12-ENG |
| 17.1 | 17.1.0 through 17.1.3 before the hotfix | Hotfix-BIGIP-17.1.3.5.0.41.14-ENG |
F5 did not evaluate End of Technical Support trains. Unknown is not safe.
CISA’s 22 September alert names four CVEs. The JSON row for 94127 matches: vendor F5, product BIG-IP APM, CWE-122, due 25 September, ransomware Unknown, forensic triage Yes. Notes tell operators to apply the iRule “to allow for proactive forensic triage,” then install the vendor patch. That sequence is the federal instruction, not an optional extra.
CERT-EU SA 2026-013 (22 September 16:52 UTC, v1.0) and CCCS AL26-022 independently restated F5’s exploitation confirmation and the same hotfix names. CERT-EU published before F5 narrowed the CVE text to authorization-server only.
The other three KEV rows from the same catalog freeze, all due 25 September, all forensic triage Yes, all ransomware Unknown:
| CVE | Product | Why it is not today’s Daily Top |
|---|---|---|
| CVE-2026-93952 | Arista VeloCloud Orchestrator on-prem | CVSS 10.0; certificate-based Edge auth + VCO web UI; hosted already patched; 6.1 / 7.0 on-prem trains still wait for a fix |
| CVE-2026-93616 | Check Point Security Management / Log / SmartEvent | Unauth path traversal + script exec; vendor: handful of customers, 23 July; LivePatch Take 28/29 does not close it |
| CVE-2026-85102 | Check Point Security Gateway / Spark VPN | Material KEV add for the [13 September Daily Top](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/); Spark-targeted attempts since 12 September per Check Point. Already assessed. |
Why it matters
BIG-IP APM as an OAuth authorization server is the box that issues access tokens to applications. Unauthenticated RCE there is not “a reverse proxy bug.” It is the identity plane sitting on the data plane.
Two operational lies show up in every F5 incident:
- “We firewalled the management interface.” This CVE is not the GUI. The overflow is in TMM handling OAuth traffic on the virtual server. CERT-EU and F5 both say so. Closing 443 on the mgmt IP does not close the VIP.
- “We already patched APM this year.” March’s CVE-2025-53521 was a different access-policy RCE. The builds that closed it are still in this CVE’s affected window. Patch history is not inventory.
CISA-ADP’s SSVC triple — active, automatable, total — is why the due date is three days, not two weeks. BOD 26-04’s forensic-triage flag means the ticket is not closed when the hotfix ISO is on disk.
No public victim count. F5, CISA, CERT-EU, and CCCS do not name an actor, a campaign, or a ransomware affiliate. Internet-wide APM banners on X are not a census of authorization servers.
Who / what is affected
| Asset | What to assume | Status |
|---|---|---|
| BIG-IP APM 21.1.0 / 17.5.0–17.5.1 / 17.1.0–17.1.3 with an OAuth Authorization Server profile on a virtual server | In scope for CVE-2026-94127 | CONFIRMED vendor (CVE updated 23 Sep 00:45 UTC) |
| Same trains, APM as OAuth Client / Resource Server only | Not this CVE | CONFIRMED vendor |
| Appliance mode | Still in | CONFIRMED vendor |
| EoTS trains | Not evaluated | UNKNOWN; do not treat as safe |
| BIG-IP without APM, or APM without an OAuth profile on the VIP | Not this CVE | CONFIRMED vendor prerequisite |
| Hosted F5 / cloud APM | Not described in the CNA record we have | UNKNOWN; ask F5 |
| Named victims | None published | UNKNOWN |
| OT / ICS / process | Not claimed | No evidence |
| CISA ransomware field | Unknown | CONFIRMED catalog |
A virtual server that matches F5’s APM 17.1 / 17.5 / 21 configuration path — Access → Federation → OAuth Authorization Server → OAuth Profile, then that profile on an access policy attached to the VIP — is the condition to inventory. That is configuration, not a CVE PoC.
Technical context
RWP is not reproducing request bodies, heap offsets, or the iRule.
What the primary records give defenders:
- Primitive. Unauthenticated network traffic to an APM virtual server that is an OAuth authorization server. Heap overflow in TMM. RCE. No login, no user click.
- Prerequisite. Access policy and OAuth authorization-server profile on that VIP. Reachability to the VIP, not to the management plane.
- Hunting combination (F5 via CERT-EU). Repeated OAuth authentication failures, then suspicious commands, then a TMM SIGABRT shortly after. That trio is the human-review trigger. Any one of them alone is not a confirmed compromise.
- Logs.
/var/log/apm: failed UserInfo requests, error description “The access token is invalid,” especially 10 or more from one IP in a short window.tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed: unexplained rise intotal_failed./var/log/auditaround those timestamps. TMM core files: investigate, do not treat as proof by themselves. F5 has seen TMM loop until SOD sends SIGABRT. - Hotfix vs. access. F5, CISA, and CERT-EU do not say the hotfix removes a foothold already taken. That is why the iRule is triage before the ISO, and why hunting is not optional.
ATT&CK mapping for what is stated:
- Exploit public-facing application (T1190) against the APM VIP.
- Command execution on a network device / appliance (T1059 class) after the overflow.
- Application access token abuse (T1550.001 class) is a follow-on risk of owning an authorization server; it is not observed tradecraft in the records we have.
Follow-on that is not claimed: a named APT, ransomware-Known, token theft as observed, or OT/process impact.
Threat / exploitation status
| Claim | Status | Basis |
|---|---|---|
In KEV, added 22 Sep, due 25 Sep, catalog 2026.09.22 count 1721 | CONFIRMED | CISA alert + JSON |
| Exploitation in the wild | CONFIRMED | F5 advisory language; KEV criterion; CERT-EU; CCCS |
| Unauthenticated RCE, data plane, appliance mode in | CONFIRMED | F5 CNA |
| OAuth Authorization Server only | CONFIRMED as of 23 Sep 00:45 UTC CVE update | F5 CNA; KEV text still broader |
| iRule then hotfix | CONFIRMED as CISA notes + vendor workaround | CISA JSON notes; F5 workarounds |
| Victim count / actor | UNKNOWN | No named set in F5, CISA, CERT-EU, CCCS |
| Ransomware use | Unknown | Catalog field |
| Forensic triage required | Yes | Catalog field |
| SSVC active / automatable / total | CONFIRMED as CISA-ADP | NVD |
| OT / physical-process impact | Not claimed | No evidence |
High confidence on: CVE ID, KEV dates, due date, catalog version and count, CVSS 9.8/9.3, CWE-122, hotfix names, forensic-triage flag, ransomware Unknown, data-plane/appliance-mode language, authorization-server narrowing in the 23 September CVE update. Moderate confidence that internet-reachable OAuth VIPs are the dominant real-world condition (SSVC automatable + data-plane; no public census). Low confidence on CISA’s unpublished exploitation evidence, on any victim identity, and on whether the hotfix displaces an existing implant.
What defenders should do
- Inventory APM OAuth Authorization Server VIPs, not “every BIG-IP.” Virtual server, access policy, OAuth profile, software train, hotfix build, and whether that VIP is reachable from untrusted networks. Record internet exposure for BOD 26-04. A tmsh walk of access policies and OAuth profiles is the ticket, not a banner grab.
- Preserve, then iRule, then hotfix. CISA’s notes are ordered that way. Snapshot logs (
/var/log/apm,/var/log/audit, TMM cores,tmctl global_oauth_stat) before you reboot onto the ENG ISO. Get the iRule from F5 Support; apply it to the affected virtual server; then install the train-matched hotfix and confirmtmsh show sys versionshows the ENG build.
- Hunt the F5 combination, not a single log line. Ten-plus invalid-token UserInfo failures from one IP, unexplained
total_failed, audit commands in that window, TMM SIGABRT shortly after. Escalate that set. Do not close “no web shell on disk.” This is TMM.
- Do not treat March’s APM patch as this patch. If the box is on 17.1.3 or 17.5.1.3 for CVE-2025-53521 and still serves as an authorization server, it is still in the 94127 window until the ENG hotfix.
- Management lockdown is hygiene, not mitigation. Restrict the GUI anyway. It does not close this CVE. CCCS still recommends it as defense-in-depth.
- Sequence the rest of Friday’s federal list. Same due date, same catalog freeze: [Check Point VPN CVE-2026-85102](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/) (now KEV; LivePatch Take 24 was last week’s close), Check Point management CVE-2026-93616 (sk1000171; Take 28/29 is not this bug), Arista VeloCloud CVE-2026-93952 (on-prem VCO, certificate-based Edge auth, 5.2.3.16 / 6.4.2.8; 6.1 and 7.0 still waiting). [Zyxel CVE-2026-7273](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/) is due tomorrow.
This is not an exploitation guide. Use F5’s hotfix table and the OAuth-role inventory.
RWP assessment
Score 8.9. Same-day vendor confirmation, CISA KEV, a three-day BOD 26-04 clock, unauthenticated RCE on the identity plane, and a data-plane condition that makes “we closed mgmt” a false close. That is the highest-leverage row in catalog 2026.09.22.
It outranks CVE-2026-93952 (Arista VCO, CVSS 10.0, actively exploited, hosted already patched, certificate-based Edge prerequisite, two trains still unfixed) as a daily because F5 APM as an OAuth issuer is the broader enterprise identity control plane and the vendor record is tighter on primitive, plane, and hotfix. It outranks CVE-2026-93616 (Check Point management, handful of July 23 victims, LivePatch coverage gap) for the same reason: targeted management vs. automatable data-plane RCE. It outranks the CVE-2026-85102 KEV add because that VPN pair was already [13 September’s Daily Top](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/); the new fact is the catalog row, not the bug. It outranks UTA0565’s Chrome–Windows chain (CVE-2026-85046 / 87491 / 85880) as a first-day identity-appliance story — Chromium 87491 has been on KEV since 9 September. It outranks ShinyHunters’ FBI/PeopleSoft claim (REPORTED, unconfirmed by the Bureau as of this writing). [Zyxel 7273](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/) is yesterday.
The failure mode to sand down is “APM is patched” and its twin, “OAuth is only for developers.” If the VIP still issues tokens on an unhotfixed 17.1 / 17.5 / 21.1 box, you are in CISA’s denominator. If you only grepped the management ACL, you inventoried the wrong socket.
What we are watching
- Whether F5 names a victim class, an actor, or a build that removes existing access.
- Whether CISA revises the KEV sentence to match the authorization-server-only CVE update.
- Whether ransomware-use flips off Unknown.
- Friday’s close rate on the other three
2026.09.22rows, especially Check Point 93616 vs. LivePatch Take 28/29 confusion and Arista 6.1 / 7.0 trains still without a listed fix. - Any attempt to treat an APM compromise in front of an industrial app as OT impact without process evidence.
Sources
- CISA — Adds four KEV (22 September 2026)
- CISA KEV JSON feed
- CISA Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- F5 — K000162605, CVE-2026-94127
- CVE.org — CVE-2026-94127
- NVD — CVE-2026-94127
- CERT-EU — Security Advisory 2026-013 (22 September 2026)
- CCCS — AL26-022 F5 BIG-IP APM (22 September 2026)
- The Hacker News — F5 patches critical BIG-IP APM zero-day (23 September 2026)
- BleepingComputer — F5 patches BIG-IP APM zero-day exploited in RCE attacks (23 September 2026)
- Arista — Security Advisory 0183, CVE-2026-93952
- Check Point — sk1000171, CVE-2026-93616
- Check Point — advisory on 85102 and 93616
- [RWP Daily Top, 22 September 2026 — Zyxel CVE-2026-7273](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/)
- [RWP Daily Top, 13 September 2026 — Check Point CVE-2026-85102 / 85103](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/)
- [RWP Daily Top, 18 September 2026 — Check Point CVE-2026-91843](/posts/2026-09-18-checkpoint-mgmt-cve-2026-91843-root-rce/)
Sources
- CISA — Adds four KEV including CVE-2026-94127
- CISA — KEV JSON feed catalog 2026.09.22
- CISA — Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- F5 — K000162605 BIG-IP APM CVE-2026-94127
- CVE — CVE-2026-94127
- NVD — CVE-2026-94127
- CERT-EU — Security Advisory 2026-013
- CCCS — AL26-022 F5 BIG-IP APM CVE-2026-94127
- The Hacker News — F5 patches critical BIG-IP APM zero-day
- BleepingComputer — F5 patches BIG-IP APM zero-day exploited in RCE attacks
- CISA — Adds one KEV CVE-2026-7273