CVE-2026-94127: F5 BIG-IP APM OAuth Heap Buffer Overflow RCE Under Active Exploitation
F5 has released an out-of-band security advisory addressing a critical remote code execution vulnerability in BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127. The flaw allows unauthenticated remote attackers to trigger a heap-based buffer overflow within the OAuth token verification engine, gaining complete root execution on affected edge application delivery controllers.
Vulnerability Mechanics & Heap Memory Corruption
When BIG-IP APM operates as an OAuth 2.0 Authorization Server, incoming client authentication requests containing JSON Web Tokens (JWT) are processed by the internal apmd policy daemon. While decoding Base64URL-encoded token claims with oversized padding characters, the memory allocation routine underestimates the required destination heap buffer.
/* Decompiled apmd token parser routine */
int process_oauth_claims(char *raw_jwt_claim, size_t claim_len) {
char *dest_buf = (char *)malloc(claim_len / 4 * 3); // Under-allocation calculation flaw
/* Vulnerable copy: overflows dest_buf during Base64URL transformation */
base64url_decode(raw_jwt_claim, dest_buf, claim_len);
return parse_json_ast(dest_buf);
}
Because the overflow occurs on the heap within apmd, attackers can overwrite adjacent function pointers to hijack control flow, executing arbitrary shellcode in the context of the root-privileged daemon.
In-the-Wild Threat Activity & IOCs
CISA added CVE-2026-94127 to the KEV catalog following detections of automated exploit scanners spraying malformed OAuth headers against enterprise internet-facing VIPs.
alert http $EXTERNAL_NET any -> $F5_VIP 443 (msg:"COLIBRISEC - F5 BIG-IP APM CVE-2026-94127 OAuth Heap Overflow Attempt"; flow:established,to_server; content:"POST"; http_method; content:"/oauth/v1/token"; http_uri; pcre:"/grant_type=[^&]*(%[0-9a-fA-F]{2}){1024,}/"; classtype:attempted-admin; sid:202694127; rev:1;)Remediation & Mitigation
- Apply Engineering Hotfixes: Update BIG-IP APM installations to hotfix releases (17.1.1.4-ENG, 17.5.0.2-ENG, 21.1.0.1-ENG).
Temporary iRule Workaround: If hotfixing cannot be executed immediately, deploy an iRule to block oversized OAuth authorization headers:
when HTTP_REQUEST {
if { [HTTP::uri] starts_with "/oauth/v1/token" and [string length [HTTP::payload]] > 4096 } {
reject
}
}