Canadian Cyber Security Journal
SOCIAL:
Filed under: TechTalk

F5 BIG-IP APM Zero-Day Gives Attackers Code Execution Without a Login

What Happened

F5 confirmed active exploitation of F5 BIG-IP APM CVE-2026-94127, a heap-based buffer overflow rated 9.8 on CVSS v3.1. The flaw affects BIG-IP Access Policy Manager systems serving as an OAuth authorization server. Crafted traffic sent to the virtual server hosting the OAuth profile leads to remote code execution without authentication. F5 disclosed the bug on September 22 and released engineering hotfixes for the 21.1, 17.5, and 17.1 branches.

CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day and gave federal agencies until September 25 to act. Neither F5 nor CISA has named the attackers or the number of victims. Read the full report from The Hacker News.

Why This Matters for Canadian Organizations

BIG-IP APM controls remote access and single sign-on for many Canadian banks, insurers, hospitals, and federal and provincial departments. An appliance issuing OAuth tokens sits at the centre of identity trust. An attacker running code on it gains a foothold to intercept sessions and move toward every application behind it.

Two details raise the stakes. First, locking down the management interface offers no protection, because the attack arrives through the public-facing virtual server. Second, systems patched for the earlier APM flaw CVE-2025-53521 remain exposed. Financial institutions under OSFI Guideline B-13 should treat this as a priority technology risk. The flaw also matches repeated Canadian Centre for Cyber Security warnings about edge devices as an entry point for attackers.

What to Do

Identify every BIG-IP system with an OAuth authorization server profile attached to a virtual server. Systems using APM only as an OAuth client or resource server are not affected. Preserve forensic evidence first, then apply the hotfix for your branch. If the hotfix must wait, request F5’s iRule mitigation through a support ticket. Review /var/log/apm for repeated “The access token is invalid” errors from a single IP, check /var/log/audit for suspicious commands, and investigate any TMM core files. Versions past End of Technical Support were not assessed, so treat them as exposed.

Follow related vulnerability analysis in our TechTalk section and daily coverage in News.

Enjoy this article? Don’t forget to share.