CVE-2026-94127
BIG-IP APM OAuth vulnerability allows unauthenticated remote code execution (CVE-2026-94127)
BIG-IP APM configured as an OAuth Authorization Server is vulnerable to unauthenticated remote code execution. CISA lists CVE-2026-94127 as exploited in the KEV catalogue. Apply the engineering hotfixes for affected BIG-IP branches.
What happened
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, and the APM is acting as an OAuth Authorization Server, specific malicious traffic can lead to remote code execution.
The attack is reachable over the network with no authentication or user interaction. It is a data plane issue; there is no control plane exposure. BIG-IP systems in Appliance mode are also vulnerable.
CISA's KEV catalogue lists the CVE as exploited, and CISA's SSVC assessment records exploitation as active.
Who is affected
BIG-IP systems running APM with an OAuth Authorization Server profile are affected. The affected version ranges are 21.1.0 to before Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, 17.5.0 to before Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, and 17.1.0 to before Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.
Deployments using APM strictly as an OAuth Client or Resource Server, without OAuth authorization server profiles configured, are not affected. Software versions that have reached End of Technical Support were not evaluated.
What to do now
- Confirm whether any BIG-IP APM virtual server has an OAuth Authorization Server profile. If it does, treat the system as affected until patched.
- Apply the appropriate vendor engineering hotfix for your branch:
- BIG-IP Hotfix-BIGIP-21.1.0.2.0.30.22-ENG for the 21.1.0 branch
- BIG-IP Hotfix-BIGIP-17.5.1.9.0.160.12-ENG for the 17.5.0 branch
- BIG-IP Hotfix-BIGIP-17.1.3.5.0.41.14-ENG for the 17.1.0 branch
- CISA's KEV entry requires mitigations in accordance with vendor instructions and BOD 26-04, including evaluating each asset's internet exposure. The listed due date is 25 September 2026.
- If you cannot apply a hotfix immediately, restrict network access to the affected virtual server as far as the OAuth service allows and monitor for unexpected activity.
Beyond the patch
Because CISA's KEV and SSVC assessments list this as actively exploited, and it is a network-reachable, unauthenticated remote code execution flaw in a common access gateway, the priority after patching is to confirm what was exposed and how quickly it would be noticed. Our Virtual CISO Services help map and reduce internet-facing access paths, and our Managed Detection & Response (MDR) can watch for post-exploitation behaviour on systems that were vulnerable before the hotfix was applied.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| BIG-IP | 21.1.0 – < Hotfix-BIGIP-21.1.0.2.0.30.22-ENG 17.5.0 – < Hotfix-BIGIP-17.5.1.9.0.160.12-ENG 17.1.0 – < Hotfix-BIGIP-17.1.3.5.0.41.14-ENG | Hotfix-BIGIP-21.1.0.2.0.30.22-ENG Hotfix-BIGIP-17.5.1.9.0.160.12-ENG Hotfix-BIGIP-17.1.3.5.0.41.14-ENG |