PT-2026-96761 · F5 · Big-Ip Apm
CVE-2026-94127
·
Published
2026-09-22
·
Updated
2026-09-25
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BIG-IP APM version 21.1.0
BIG-IP APM versions 17.5.0 through 17.5.1
BIG-IP APM versions 17.1.0 through 17.1.3
Description
An unauthenticated heap-based buffer overflow exists in the data plane of BIG-IP APM when configured as an OAuth Authorization Server with an access policy and an OAuth profile on a virtual server. A remote attacker can trigger this issue by sending malicious network traffic, specifically a GET request to the
/f5-oauth2/v1/userinfo endpoint containing an oversized Authorization header (exceeding 0x4100 bytes). This leads to heap corruption in the tmm64 traffic management microkernel, allowing for remote code execution (RCE) without user interaction. The vulnerability is also present in Appliance mode. This issue has been confirmed as exploited in the wild, and over 14,700 IP addresses with BIG-IP APM fingerprints have been identified globally.Recommendations
For BIG-IP APM version 21.1.0, apply
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso.
For BIG-IP APM versions 17.5.0 through 17.5.1, apply Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso.
For BIG-IP APM versions 17.1.0 through 17.1.3, apply Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso.
As a temporary mitigation, request and apply the specific iRule from F5 Support for the affected virtual servers.
Restrict access to affected virtual servers at a trusted upstream boundary to reduce exposure.Fix
LPE
RCE
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Big-Ip Apm