An unauthenticated attacker can run code on F5 BIG-IP APM with one oversized Bearer token — but only when APM is configured as an OAuth Authorization Server.
F5 BIG-IP sits at the edge of a large share of enterprise networks, terminating TLS, load-balancing traffic and, through the Access Policy Manager (APM) module, acting as a remote-access and single-sign-on gateway. A new critical flaw turns one of those APM deployments into an unauthenticated remote-code-execution target, and the trigger is almost insultingly simple: send an HTTP request with an oversized Authorization: Bearer header.
The bug is tracked as CVE-2026-94127. F5 scores it CVSS 9.8 (Critical) on v3.1 and 9.3 (Critical) on v4.0. It was published on 22 September 2026, and CISA added it to the Known Exploited Vulnerabilities catalog the same day, with a federal remediation deadline of 25 September — a three-day window. CISA's own decision data marks the exploitation as active, the attack as automatable, and the technical impact as total.
The exposure is narrow, and that is the catch
This is not a blanket "every BIG-IP is on fire" advisory, and the detail that decides whether you are affected is easy to miss. The vulnerability exists only when BIG-IP APM is configured as an OAuth Authorization Server — an access policy plus an OAuth profile bound to a virtual server. F5 is explicit that deployments using APM strictly as an OAuth Client or Resource Server, without any authorization-server profile, are not affected. Other BIG-IP modules are not affected, and BIG-IQ Centralized Management is not affected.
So the real work for defenders is inventory: finding which of your APM boxes are acting as an OAuth Authorization Server. Those are the exposed ones. F5 also notes that the BIG-IP system is vulnerable even in Appliance mode, and that this is a data-plane issue with no control-plane exposure — meaning the attack comes through the same virtual server that serves users, not the management interface.
F5's advisory, the NVD record and the CISA KEV listing for CVE-2026-94127 all landed on 22 September, with a 25 September federal deadline.
What actually breaks
F5 classifies the flaw as a heap-based buffer overflow (CWE-122). watchTowr Labs, which published a root-cause analysis on 23 September 2026, traced it to the tmm64 traffic-management process that handles the OAuth userinfo flow.
The mechanism, from watchTowr's patch diff, is a textbook missing-bounds-check. The handler allocates a fixed heap buffer of 0x4100 bytes (16,640 bytes) for the incoming Authorization header, but the vulnerable build copied the header into that buffer without first checking its length. The patch adds exactly that check: if the header exceeds 0x4100, the request is now rejected with the error "Authorization header too big." watchTowr summed it up as a primitive "from 20 years ago," sitting in the code path that handles security credentials.
Triggering the crash is as simple as the fix is small. A single request to an OAuth userinfo endpoint — watchTowr used /f5-oauth2/v1/userinfo — carrying a Bearer token larger than 16,640 bytes overflows the buffer and corrupts adjacent heap data, dropping tmm64. Turning that crash into code execution is harder (the appliance ships with ASLR and a stack canary, and SELinux blocks the obvious paths), but watchTowr demonstrated a full working exploit, so defenders should treat RCE as proven, not theoretical.
The attack path: an oversized Bearer token is copied into a fixed 16,640-byte heap buffer with no length check, overflowing tmm64 and leading to remote code execution.
What to do
- Find your exposed boxes first. The only affected configuration is APM acting as an OAuth Authorization Server. Audit APM virtual servers for an OAuth profile with authorization-server settings; those are the ones to prioritize.
- Apply F5's fix. The remedies are engineering hotfixes, not general-availability point releases —
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG,Hotfix-BIGIP-17.5.1.9.0.160.12-ENGandHotfix-BIGIP-17.1.3.5.0.41.14-ENG— so locating and staging the right hotfix for each box is part of the job. - Hunt in the meantime. Because the overflow needs an outsized header, requests to OAuth userinfo endpoints carrying an
Authorizationheader well over 16 KB are a strong signal, as are unexplainedtmm64restarts on an OAuth-serving virtual server. CISA's KEV listing also directs agencies to its forensic-triage guidance before assuming a box is clean.
Affected versions
| BIG-IP APM branch | Affected versions | Fixed in (engineering hotfix) |
|---|---|---|
| 21.x | 21.1.0 | Hotfix-BIGIP-21.1.0.2.0.30.22-ENG |
| 17.5.x | 17.5.0 – 17.5.1 | Hotfix-BIGIP-17.5.1.9.0.160.12-ENG |
| 17.1.x | 17.1.0 – 17.1.3 | Hotfix-BIGIP-17.1.3.5.0.41.14-ENG |
Only applies when APM is configured as an OAuth Authorization Server. Versions past End of Technical Support were not evaluated by F5.