{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-F71F16D9",
  "slug": "cve-2026-94127-f5-big-ip-apm-oauth-rce-kev",
  "title": "F5 BIG-IP APM OAuth VIP can run attacker code with no login",
  "aliases": [
    "CVE-2026-94127",
    "K000162605",
    "F5 BIG-IP APM OAuth RCE"
  ],
  "summary": "F5 disclosed CVE-2026-94127 on 2026-09-22: heap overflow RCE on BIG-IP APM when access policy and OAuth share a VIP. Unauthenticated. Appliance mode included. CISA added it to KEV the same day. Fixed by ENG hotfixes Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG. Temporary iRule available via F5 Support for triage before patch.",
  "status": "published",
  "severity": "critical",
  "confidence": "high",
  "uncertainty": "Secondary reporting expands version ranges to 17.5.0-17.5.1 and 17.1.0-17.1.3; CNA lists branch starts 21.1.0 / 17.5.0 / 17.1.0 lessThan the named ENG hotfixes. Confirm exact build from MyF5 before closing.",
  "firstObservedAt": "2026-09-22T14:17:42.730Z",
  "lastObservedAt": "2026-09-22T19:02:09.978Z",
  "publishedAt": "2026-09-22T20:06:15.209Z",
  "reviewedAt": "2026-09-22T20:05:52.287Z",
  "expiresAt": "2026-09-22T19:02:09.978Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "src-f5",
      "label": "F5 K000162605",
      "url": "https://my.f5.com/manage/s/article/K000162605",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-09-22T14:00:00.000Z"
    },
    {
      "id": "src-cve",
      "label": "CVE-2026-94127 CVE record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94127",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-22T14:17:42.730Z"
    },
    {
      "id": "src-nvd",
      "label": "NVD CVE-2026-94127",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-94127",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-09-22T15:17:24.313Z"
    },
    {
      "id": "src-kev",
      "label": "CISA KEV catalog 2026.09.22",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "sourceType": "government",
      "observedAt": "2026-09-22T19:02:09.978Z"
    },
    {
      "id": "src-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-94127-f5-big-ip-apm-oauth-rce-kev",
      "sourceType": "other_primary",
      "observedAt": "2026-09-22T19:58:20.652Z"
    }
  ],
  "artifacts": [
    {
      "id": "art-bigip-apm",
      "artifactClass": "package",
      "ecosystem": "generic",
      "name": "F5 BIG-IP APM",
      "version": "21.1.0 / 17.5.x / 17.1.x before ENG hotfixes",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "tl-f5",
      "occurredAt": "2026-09-22T14:00:00.000Z",
      "eventType": "disclosure",
      "summary": "F5 publishes BIG-IP APM OAuth RCE advisory K000162605 / CVE-2026-94127",
      "sourceIds": [
        "src-f5",
        "src-cve"
      ]
    },
    {
      "id": "tl-kev",
      "occurredAt": "2026-09-22T19:02:09.978Z",
      "eventType": "registry_action",
      "summary": "CISA adds CVE-2026-94127 to KEV catalogVersion 2026.09.22 (due 2026-09-25)",
      "sourceIds": [
        "src-kev"
      ]
    },
    {
      "id": "tl-blog",
      "occurredAt": "2026-09-22T19:58:20.652Z",
      "eventType": "other",
      "summary": "HOL Guard publishes operator fix write-up",
      "sourceIds": [
        "src-blog"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "Only virtual servers with both an APM access policy and an OAuth profile are in the stated blast radius.",
    "Control plane is not the exposure path; this is a data-plane VIP issue.",
    "EoTS software versions were not evaluated by F5.",
    "Exact public POC status is not claimed here."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-94127-f5-big-ip-apm-oauth-rce-kev/corrections"
}
