Summary Points
- Attackers can exploit CVE-2026-94127 to perform remote code execution on F5 BIG-IP systems acting as OAuth authorization servers, leading to potential full system compromise.
- Malicious traffic sent directly to the vulnerable virtual server can bypass management access controls, allowing attackers to run arbitrary code without requiring login credentials.
- Unpatched systems show signs of compromise, including repeated failed OAuth requests, suspicious commands in logs, and abnormal core dumps, indicating active exploitation.
Threat, Attack Techniques, and Targets
Attackers are exploiting a critical vulnerability in F5 BIG-IP Access Policy Manager (APM). This flaw, identified as CVE-2026-94127, allows attackers to run code on affected systems without needing to log in. The vulnerability affects systems where APM functions as an OAuth authorization server that issues access tokens. The flaw involves a heap-based buffer overflow, making it highly severe with a CVSS score of 9.8 out of 10. Attackers send malicious traffic to a specific virtual server hosting the OAuth traffic. This traffic leads to remote code execution. The vulnerability impacts systems in several versions, including 21.1, 17.5, and 17.1, specifically when APM is configured as an OAuth authorization server.
The attack primarily targets virtual servers hosting both an APM access policy and an OAuth authorization server profile. These are common in configurations where the APM module controls user access to applications and networks. Notably, systems where APM acts as only an OAuth client or resource server are not impacted. This flaw’s exploitation can occur regardless of whether the management interface is protected, and even systems in Appliance mode are vulnerable. The attackers can leverage this vulnerability without requiring user authentication.
Impact, Security Implications, and Remediation Guidance
The critical nature of this flaw means it can cause severe damage if exploited. Successful exploitation grants attackers remote code execution privileges, potentially leading to system compromise. This vulnerability can undermine the security of the affected BIG-IP systems, possibly allowing attackers to control the network and access sensitive data. Because malicious traffic targets the virtual server itself, limiting access to the management interface does not prevent the attack.
F5 has issued updates with hotfixes to fix this flaw. The recommended approach is to install the specific hotfix for your system version. Customers unable to install the hotfix immediately are advised to use the iRule mitigation available through F5 support to protect their systems temporarily. CERT-EU recommends preserving evidence, applying the hotfix, checking for signs of compromise, and starting incident response if suspicious activity is found. The vulnerability’s full impact and mitigation steps should be obtained from F5 or the relevant security authority to ensure proper protection and response.
Discover More Technology Insights
Dive deeper into the world of Cryptocurrency and its impact on global finance.
Discover archived knowledge and digital history on the Internet Archive.
ThreatIntel-V1
