Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal.

SOCtember.com

Always First. Fast SOC News.

Response · NEW YORK

F5 Warns of Exploited BIG-IP APM Flaw Enabling Unauthenticated Remote Code Execution

By Noah Park, Response, New York

NEW YORK - F5 Networks has confirmed a critical heap-based buffer overflow in BIG-IP Access Policy Manager is under active exploitation, and CISA added it to the Known Exploited Vulnerabilities catalog.

CVE-2026-94127 scores CVSS 9.8 in F5's CVE record. Unauthenticated attackers with network access to an affected virtual server may get remote code execution when that server has both an APM access policy and an OAuth Authorization Server profile. APM used only as OAuth Client or Resource Server is not affected. Appliance mode is vulnerable. Data plane only; no control plane exposure.

F5 advisory K000162605 (Sept 22, 2026) says exploitation has been learned. Hunt multiple OAuth auth failures and suspicious commands shortly before a TMM SIGABRT. Temporary mitigation: vendor iRule via F5 Support. Hotfixes: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.

CISA KEV dateAdded Sept 22, 2026; federal due Sept 25, 2026; forensic triage under BOD 26-04. BleepingComputer cited Shadowserver tracking more than 14,700 internet-facing BIG-IP APM fingerprints as of Sept 23, 2026 (not limited to vulnerable configs).

SOC work: inventory those APM+OAuth Authorization Server virtual servers, prioritize untrusted-network exposure, apply hotfix or iRule, hunt the OAuth-failure/TMM-abort pattern, and on compromise review credentials and sessions.

Noah Park covers incident response and blue-team operations for SOCtember from New York.

Back to Response