Full Report
AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127
Analysis Summary
# Vulnerability: F5 BIG-IP APM Heap-based Buffer Overflow
## CVE Details
- **CVE ID:** CVE-2026-94127
- **CVSS Score:** Critical (Specific numerical score not provided in text, but categorized as a critical vulnerability)
- **CWE:** CWE-122 (Heap-based Buffer Overflow)
## Affected Systems
- **Products:** F5 BIG-IP Access Policy Manager (APM)
- **Versions:**
- 17.1.0 (Prior to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG)
- 17.5.0 (Prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG)
- 21.1.0 (Prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG)
- **Configurations:** Systems where an **APM access policy** and an **OAuth profile** are configured on the same virtual server.
## Vulnerability Description
The flaw is a heap-based buffer overflow triggered by specially crafted malicious traffic. In vulnerable configurations, this allows an unauthenticated attacker to execute arbitrary code on the device. This can lead to full system compromise and remote code execution (RCE).
## Exploitation
- **Status:** **Exploited in the wild.** F5 has confirmed active exploitation.
- **Complexity:** Not explicitly stated, but implies high impact for unauthenticated actors.
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Potential for full system compromise)
- **Integrity:** High (Arbitrary code execution)
- **Availability:** High (System compromise/Disruption)
## Remediation
### Patches
Organizations should upgrade to the following fixed versions immediately:
- **17.1.0:** Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
- **17.5.0:** Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
- **21.1.0:** Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
### Workarounds
- **iRule Mitigation:** Contact F5 Support to obtain a vendor-provided iRule that can mitigate the risk until patches are applied.
- **Network Hardening:** Restrict management interfaces to trusted administrative networks only.
## Detection
- **Log Analysis:** Review access logs for OAuth authentication failures, specifically those occurring in rapid succession or high volumes.
- **Policy Audit:** Inspect administrative accounts and access policies for unauthorized changes or suspicious activity.
- **Traffic Monitoring:** Monitor for indicators of compromise (IoC) associated with heap overflow exploitation attempts against APM virtual servers.
## References
- Vendor Advisory (F5): hxxps://my.f5[.]com/manage/s/article/K000162605
- Cyber Centre Alert: hxxps://www.cyber.gc[.]ca/en/alerts-advisories/al26-022-vulnerability-impacting-f5-big-ip-access-policy-manager-apm-cve-2026-94127
- NVD Detail: hxxps://nvd.nist[.]gov/vuln/detail/cve-2026-94127