OFFSEC · Offensive Security

The F5 hotfix closes the overflow. It does not revoke the tokens

CVE-2026-94127 gives an unauthenticated attacker code execution on BIG-IP APM where it is configured as an OAuth authorization server. F5 confirms exploitation before disclosure. Remediation is not finished when the hotfix is applied, because the appliance signs tokens that F5's own documentation says cannot be revoked.

What was disclosed

F5 published an advisory for CVE-2026-94127 on 22 September 2026 and stated that the vulnerability had been exploited [6]. CERT-EU issued advisory 2026-013 the same day, recording a heap-based buffer overflow allowing an unauthenticated attacker to execute code on the device, with CVSS 9.8 [2]. Tenable records the v3.1 vector as CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H and a v4.0 score of 9.3 [7]. The fault class is CWE-122: a heap buffer written past its bounds, which permits overwriting function pointers and redirecting execution [10].

Affected versions are BIG-IP APM 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3, with engineering hotfixes for each branch [2][5]. The condition is narrow: APM must be running as an OAuth authorization server, with an access policy and an OAuth profile on a virtual server [2][7]. Client and resource server deployments are not affected [4][7]. F5 calls it a data plane issue with no control plane exposure, and says appliance mode is also vulnerable [6]. Where patching must wait, F5 offers an iRule mitigation through support [2][3].

Sources disagree on discovery. SecurityWeek reports F5 found the flaw internally [4]; BleepingComputer records that F5 did not say who found or reported it [3]. watchTowr published an analysis on 23 September, derived from diffing the vulnerable build against the hotfix, locating the defect in handling of the Authorization header on the OAuth path [1].

Why the hotfix is not the end of it

An OAuth authorization server is not an ordinary reverse proxy. It decides who a user is and issues the credential downstream applications accept. F5's documentation for APM in that role is explicit about two properties that matter after a compromise.

  • APM issues access tokens and, where enabled, refresh tokens, in either opaque or JWT format. Opaque tokens are stored on the issuing server for their lifetime and only it can validate them [9].
  • JWTs are self-contained and signed. F5 states that JSON tokens are not stored on an OAuth authorization server and cannot be revoked [9]. Signing uses configured JSON Web Keys; the system also holds a JWT refresh token encryption secret and resource server secrets [9].

Put those next to unauthenticated code execution on the same device. An attacker who reached the file system could take the signing material, and tokens minted with it are indistinguishable from legitimate ones to every resource server that trusts the issuer. The property that makes JWTs cheap to validate – no lookup, no server-side state – is the property that makes them impossible to withdraw. The hotfix closes the intrusion path. It does nothing about a key that has already left.

Remediation scope therefore includes the trust material: JWK signing keys, the refresh token encryption secret, resource server and client secrets, and any directory credentials the access policy uses. With opaque tokens, sessions can be invalidated at the server. With JWTs they cannot, and short lifetimes are the only mitigation until the key changes. None of this appears in a patch advisory, because advisories are written about code.

The deadline says the same thing in a different way

CISA added CVE-2026-94127 to the Known Exploited Vulnerabilities catalogue on 22 September, alongside two Check Point flaws and one in Arista VeloCloud Orchestrator, with a remediation date of 25 September [8]. The governing directive is BOD 26-04, Prioritizing Security Updates Based on Risk, which requires agencies to patch internet-facing assets and to carry out forensic triage establishing whether systems were compromised before the patch landed [8]. Sources differ on the date: BleepingComputer reported 27 September [3], other coverage gives 25 September [5][6][8]. Work to the earlier one.

The forensic triage clause is worth reading twice. A directive that separates patching from compromise assessment concedes that the patch is not the answer to the question. CERT-EU's guidance is structured the same way: preserve evidence, apply hotfixes, assess for compromise [2].

The indicators are usable, and better than in most appliance cases. CERT-EU and F5 point to multiple OAuth authentication failures from a single source address, unexpected increases in OAuth failure statistics, suspicious commands in audit logs correlating with those failures, and TMM core file generation [2][6]. BleepingComputer records F5's phrasing as OAuth authentication failures and suspicious commands shortly followed by a TMM SIGABRT [3]; watchTowr adds an oversized Authorization header to an OAuth endpoint as the network-side signature [1]. That combination is observable off the device, in load balancer logs, WAF telemetry and network capture – which matters, because root on the appliance means the on-box logs are writable by the attacker.

The exposure figure, and the one nobody publishes

Shadowserver counted more than 14,700 IP addresses presenting BIG-IP APM fingerprints [3][6]. No retrievable source states how many of those run the vulnerable OAuth authorization server configuration, and the honest position is that the number is unknown [6].

History shows how the population behaves. In April 2026, after a different exploited pre-authentication APM flaw – CVE-2025-53521, added to KEV with a 31 March federal deadline – Shadowserver tracked over 17,100 fingerprinted IPs with more than 14,000 still exposed, under the same caveat about configuration [11]. F5's guidance then included rebuilding affected systems from known-good sources, because UCS configuration archives from a compromised device can carry persistent malware [11]. Two exploited pre-authentication flaws in one module inside six months, against a population that barely moves, is the pattern to plan around.

One triage input performed badly. EPSS for CVE-2026-94127 stood at 0.01391 while the vendor confirmed exploitation and the national authority set a three-day clock [7]. A prioritisation process weighted on that score would have deferred this.

Context that belongs in the risk assessment

In October 2025 F5 disclosed a long-running intrusion by what it described as a nation-state affiliated actor, including access to portions of BIG-IP source code and to information on vulnerabilities the company was still patching [12]. CISA issued Emergency Directive 26-01 in response [12]. Resecurity assesses the intrusion as the work of the China-nexus cluster tracked as UNC5221, using the BRICKSTORM backdoor, with access for at least twelve months, and assesses that the stolen material shortens the path from bug to working exploit [13]. That is Resecurity's assessment, not an R3KONX finding, and no source connects it to CVE-2026-94127.

It belongs in the file because it sets a prior. Source code and pre-disclosure vulnerability data in capable hands makes a quiet pre-authentication exploit in this product line likelier than the base rate suggests, which argues for treating compromise assessment as the default.

Regional note

No Malaysian national advisory for this CVE could be identified as at publication; NACSA's alerts page lists nothing after 30 June 2026 [14]. CERT-EU's 2026-013 remains the most complete public advisory located [2]. Operators relying on a national CERT to prompt a patch cycle on an internet-facing identity gateway should not, on this evidence, expect the prompt.

What to do

  • Establish whether APM is acting as an OAuth authorization server, per virtual server. That is the applicability question, and it is a configuration fact, not a version fact [2][7].
  • Preserve evidence before you patch, then patch, then assess [2]. The order is not decorative.
  • Hunt off the box: OAuth failure spikes from single sources, oversized Authorization headers to OAuth endpoints, TMM core files and SIGABRT events, unexpected egress from the appliance subnet [1][2][3][13].
  • Treat signing material as compromised where you cannot rule out exploitation. Rotate JWK signing keys, the refresh token encryption secret, client and resource server secrets, and directory credentials held by the access policy [9].
  • Shorten long JWT lifetimes now. Until keys rotate, lifetime is the only revocation available [9].
  • Do not restore configuration archives taken from a device you cannot clear [11].
  • Remove management interfaces from the internet and restrict appliance egress [13].

Domain close

Edge appliances get treated as network equipment: patched on the network team's cadence, audited as infrastructure. BIG-IP APM configured this way is not network equipment. It is an identity provider with a signing key, and the blast radius of code execution on it is every application that trusts its tokens. The hotfix is the easy half. The rotation plan is the half that decides whether the intrusion ended in September.

Sources

Every R3KONX article cites its primary material. 14 sources, in order of first citation. Links open the original publication.

  1. Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) watchTowr Labs · 2026-09-23
  2. Critical Vulnerability in F5 BIG-IP APM (advisory 2026-013) CERT-EU · 2026-09-22
  3. F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks BleepingComputer · 2026-09-23
  4. Critical F5 BIG-IP Vulnerability Exploited as Zero-Day SecurityWeek · 2026-09-23
  5. F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers The Hacker News · 2026-09-23
  6. F5 BIG-IP APM zero-day exploited in RCE attacks Security Affairs · 2026-09-23
  7. CVE-2026-94127 Tenable · 2026-09-22
  8. CISA KEV: F5, Check Point and Arista Flaws Due September 25 WindowsForum · 2026-09-22
  9. About OAuth Authorization Server, BIG-IP Access Policy Manager: OAuth Configuration F5 Networks (techdocs) · 2026-01-01
  10. CWE-122: Heap-based Buffer Overflow MITRE · 2026-01-01
  11. Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks BleepingComputer · 2026-04-02
  12. F5 Breach Exposes BIG-IP Source Code - Nation-State Hackers Behind Massive Intrusion The Hacker News · 2025-10-15
  13. F5 BIG-IP Source Code Leak Tied to State-Linked Campaigns Using BRICKSTORM Backdoor Resecurity · 2025-10-22
  14. Alert and Advisories National Cyber Security Agency (NACSA), Malaysia · 2026-06-30

Researched and written by the R3KONX analysis desk from the cited primary material. Methodological caveats: F5's advisory K000162605 could not be retrieved directly, so its contents are carried from CERT-EU and from the publishers named in each citation; cisa.gov was unreachable from this desk, so the KEV listing date and directive reference are carried from secondary publishers rather than attributed to CISA's own pages. No exploitation mechanics are reproduced. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.