PT-2026-96761 · F5 · Big-Ip Apm

CVE-2026-94127

·

Published

2026-09-22

·

Updated

2026-09-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BIG-IP APM version 21.1.0 BIG-IP APM versions 17.5.0 through 17.5.1 BIG-IP APM versions 17.1.0 through 17.1.3
Description An unauthenticated heap-based buffer overflow exists in the data plane of BIG-IP APM when configured as an OAuth Authorization Server with an access policy and an OAuth profile on a virtual server. A remote attacker can trigger this issue by sending malicious network traffic, specifically a GET request to the /f5-oauth2/v1/userinfo endpoint containing an oversized Authorization header (exceeding 0x4100 bytes). This leads to heap corruption in the tmm64 traffic management microkernel, allowing for remote code execution (RCE) without user interaction. The vulnerability is also present in Appliance mode. This issue has been confirmed as exploited in the wild, and over 14,700 IP addresses with BIG-IP APM fingerprints have been identified globally.
Recommendations For BIG-IP APM version 21.1.0, apply Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso. For BIG-IP APM versions 17.5.0 through 17.5.1, apply Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso. For BIG-IP APM versions 17.1.0 through 17.1.3, apply Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso. As a temporary mitigation, request and apply the specific iRule from F5 Support for the affected virtual servers. Restrict access to affected virtual servers at a trusted upstream boundary to reduce exposure.

Fix

LPE

RCE

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94127

Affected Products

Big-Ip Apm