F5 BIG-IP APM OAuth VIP can run attacker code with no login
F5 disclosed CVE-2026-94127 on 2026-09-22: heap overflow RCE on BIG-IP APM when access policy and OAuth share a VIP. Unauthenticated. Appliance mode included. CISA added it to KEV the same day. Fixed by ENG hotfixes Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG. Temporary iRule available via F5 Support for triage before patch.
Also tracked as CVE-2026-94127 · K000162605 · F5 BIG-IP APM OAuth RCE
- First observed
- Sep 22, 2026
- Last observed
- Sep 22, 2026
- Last reviewed
- Sep 22, 2026
- Tracking ended
- Sep 22, 2026
Record exports
Uncertainty and limitations
Read the evidence limits before acting on this record.
Secondary reporting expands version ranges to 17.5.0-17.5.1 and 17.1.0-17.1.3; CNA lists branch starts 21.1.0 / 17.5.0 / 17.1.0 lessThan the named ENG hotfixes. Confirm exact build from MyF5 before closing.
- Only virtual servers with both an APM access policy and an OAuth profile are in the stated blast radius.
- Control plane is not the exposure path; this is a data-plane VIP issue.
- EoTS software versions were not evaluated by F5.
- Exact public POC status is not claimed here.
Guard coverage and policy
What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.
No Guard coverage mapping is published for this record.
No campaign-specific policy guidance is published.
Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.
Timeline
Reviewed events, oldest first, each tied to a verified source.
- Disclosure
F5 publishes BIG-IP APM OAuth RCE advisory K000162605 / CVE-2026-94127
- Registry action
CISA adds CVE-2026-94127 to KEV catalogVersion 2026.09.22 (due 2026-09-25)
- Update
HOL Guard publishes operator fix write-up
Publication clock: 6.1 hours from reviewed disclosure timestamp to HOL publication; 12-hour critical target; within target.
Reviewed artifacts
The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.
F5 BIG-IP APM@21.1.0 / 17.5.x / 17.1.x before ENG hotfixesgenericpackage
Sources
Every claim on this record is traceable to the sources below.
- F5 K000162605vendor advisory · observed September 22, 2026
- CVE-2026-94127 CVE recordvulnerability database · observed September 22, 2026
- NVD CVE-2026-94127vulnerability database · observed September 22, 2026
- CISA KEV catalog 2026.09.22government · observed September 22, 2026
- HOL Guard operator write-upother primary · observed September 22, 2026
Reviewed in full by HOL Guard Security Publishing.
- Published
- Last full review
- Last modified
Record HGTC-2026-F71F16D9