## Overview
F5 Networks disclosed a critical vulnerability in BIG-IP, tracked as CVE-2026-94127. This flaw impacts systems where the BIG-IP Access Policy Manager (APM) is configured as an OAuth Authorization Server. It allows unauthenticated attackers to execute remote code.
## Technical Details
The vulnerability arises when specific malicious traffic targets a virtual server configured with both an APM access policy and an OAuth profile. The issue is present only in configurations where BIG-IP APM operates as an OAuth Authorization Server. Systems using APM solely as an OAuth Client or Resource Server are not affected. The vulnerability is classified with a CVSS score of 9.3, indicating its high severity. It also affects the BIG-IP system in Appliance mode. This is a data plane issue, meaning there is no exposure on the control plane.
## Impact
An attacker exploiting this vulnerability can execute arbitrary code on the affected system without authentication. This poses a significant risk to organizations using the vulnerable configurations, as it can lead to unauthorized access and potential data breaches. Organizations must assess their BIG-IP deployments to determine if they are at risk.
## Mitigation
Defenders should immediately review their BIG-IP configurations. If using APM as an OAuth Authorization Server, apply the latest security patches provided by F5. Organizations should also consider disabling the OAuth Authorization Server feature if it is not necessary. Regularly monitor for updates and follow best practices for securing BIG-IP deployments to mitigate potential threats.
CSURFACE Threat Sensor