Critical F5 BIG‑IP APM Vulnerability Enables Unauthenticated Code Execution on OAuth Servers
Security researchers have confirmed that a critical vulnerability in F5 Networks' BIG‑IP Access Policy Manager (APM) is being actively exploited to achieve unauthenticated remote code execution on systems that function as OAuth authorization servers. The flaw, cataloged as CVE‑2026‑94127, allows attackers to execute arbitrary commands without needing valid credentials, posing a severe risk to enterprises that rely on F5 for secure access control.
The vulnerability is limited to BIG‑IP deployments where the APM module is configured to issue OAuth tokens. In such setups, the APM component processes authorization requests and, according to F5, the flaw stems from insufficient validation of crafted OAuth parameters, enabling malicious actors to inject code that runs with the privileges of the BIG‑IP device.
F5 Networks issued an emergency advisory on Tuesday, urging all customers with affected configurations to apply the newly released security patch immediately. The company also recommends disabling the OAuth authorization server function on APM until the update can be deployed, as a temporary mitigation to block exploitation attempts.
Industry analysts note that the timing of the exploit aligns with a broader trend of attackers targeting network infrastructure components that sit at the intersection of identity management and application delivery. Because OAuth tokens are often used to grant access to internal applications, a compromised BIG‑IP device could serve as a foothold for lateral movement within a network.
Organizations using F5 BIG‑IP for load balancing, SSL termination, or web application firewalling but not employing APM as an OAuth server are not directly affected by CVE‑2026‑94127. However, the advisory cautions that misconfigurations could inadvertently expose the vulnerable code path, underscoring the importance of thorough configuration reviews.
F5 has pledged to monitor the situation closely and will release additional guidance as more information becomes available. Security teams are advised to verify patch deployment, audit OAuth server settings, and review logs for any signs of anomalous activity that could indicate prior exploitation.
Comments (0)
Be the first to comment.
Join the discussion