CVE-2026-94127: F5 BIG-IP APM OAuth Heap Buffer Overflow RCE Under Active Exploitation

F5 BIG-IP APM CVE-2026-94127 Heap Buffer Overflow Analysis
🛡️
Vulnerability Intelligence:

F5 has released an out-of-band security advisory addressing a critical remote code execution vulnerability in BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127. The flaw allows unauthenticated remote attackers to trigger a heap-based buffer overflow within the OAuth token verification engine, gaining complete root execution on affected edge application delivery controllers.

Vulnerability Mechanics & Heap Memory Corruption

When BIG-IP APM operates as an OAuth 2.0 Authorization Server, incoming client authentication requests containing JSON Web Tokens (JWT) are processed by the internal apmd policy daemon. While decoding Base64URL-encoded token claims with oversized padding characters, the memory allocation routine underestimates the required destination heap buffer.

/* Decompiled apmd token parser routine */
int process_oauth_claims(char *raw_jwt_claim, size_t claim_len) {
    char *dest_buf = (char *)malloc(claim_len / 4 * 3); // Under-allocation calculation flaw
    /* Vulnerable copy: overflows dest_buf during Base64URL transformation */
    base64url_decode(raw_jwt_claim, dest_buf, claim_len);
    return parse_json_ast(dest_buf);
}

Because the overflow occurs on the heap within apmd, attackers can overwrite adjacent function pointers to hijack control flow, executing arbitrary shellcode in the context of the root-privileged daemon.

In-the-Wild Threat Activity & IOCs

CISA added CVE-2026-94127 to the KEV catalog following detections of automated exploit scanners spraying malformed OAuth headers against enterprise internet-facing VIPs.

🔍
Detection Rule (Snort / Suricata):
alert http $EXTERNAL_NET any -> $F5_VIP 443 (msg:"COLIBRISEC - F5 BIG-IP APM CVE-2026-94127 OAuth Heap Overflow Attempt"; flow:established,to_server; content:"POST"; http_method; content:"/oauth/v1/token"; http_uri; pcre:"/grant_type=[^&]*(%[0-9a-fA-F]{2}){1024,}/"; classtype:attempted-admin; sid:202694127; rev:1;)

Remediation & Mitigation

  1. Apply Engineering Hotfixes: Update BIG-IP APM installations to hotfix releases (17.1.1.4-ENG, 17.5.0.2-ENG, 21.1.0.1-ENG).

Temporary iRule Workaround: If hotfixing cannot be executed immediately, deploy an iRule to block oversized OAuth authorization headers:

when HTTP_REQUEST {
    if { [HTTP::uri] starts_with "/oauth/v1/token" and [string length [HTTP::payload]] > 4096 } {
        reject
    }
}

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther