Emergency application delivery security updates have been distributed to address an actively exploited zero day vulnerability in enterprise access management controllers. Unauthenticated remote actors transmit malformed OAuth authorization requests to trigger heap memory corruption and execute arbitrary code on target appliances.
The vulnerability, tracked as CVE-2026-94127 with a CVSS score of 9.8, impacts F5 BIG-IP Access Policy Manager installations configured as OAuth authorization servers. The defect involves a heap-based buffer overflow in Traffic Management Microkernel processes handling authorization requests. Unauthenticated remote adversaries transmit crafted HTTP payloads to vulnerable virtual servers, achieving remote code execution with full administrative privileges. CISA added the flaw to the Known Exploited Vulnerabilities catalog under Binding Operational Directive 26-04 with a mandatory September 25 compliance deadline.
Subverting central access management controllers destroys single sign-on boundaries and application perimeter security. Because BIG-IP APM handles user authentication, identity federation, and remote access policies for enterprise applications, an unauthenticated host compromise permits threat actors to hijack active user sessions, harvest corporate credentials, and pivot directly into backend subnets.
– Apply emergency engineering hotfixes published by F5 across all affected BIG-IP Access Policy Manager instances immediately.
– Deploy temporary mitigation iRules to intercept malformed OAuth authorization payloads where immediate patching cannot be completed.
– Inspect APM application logs in /var/log/apm for repeated failed UserInfo requests and unverified access token errors.
– Audit active single sign-on sessions and rotate OAuth client secret keys across exposed enterprise application environments.
Access control gateway defense demands immediate patch deployment and strict traffic inspection to ensure enterprise identity brokers remain completely protected from unauthenticated buffer overflow exploitation. #CodeDefence #F5 #BIGIP #APM #ZeroDay #OAuth #RCE #CISA #KEV #AppSec
/
