The front door to single sign-on had a hole, and attackers found it first

Share this content

September 24, 2026

F5 BIG-IP Access Policy Manager sits in front of a lot of important things: VPN access, single sign-on, federated logins for cloud and on-premises applications. It is the checkpoint that decides who gets in. On Sept. 22, F5 confirmed attackers had found a way to take over that checkpoint itself.

BigIP

What happened

The flaw, CVE-2026-94127, is a heap-based buffer overflow rated 9.8 on CVSS v3.1. It affects APM systems acting as an OAuth Authorization Server, the configuration where BIG-IP issues access tokens to applications. Specially crafted traffic sent to that virtual server can give an unauthenticated attacker remote code execution.

A few details make it worse:

  • Locking down the management interface does not help. The malicious traffic goes to the public-facing virtual server, not the admin port.
  • Appliance mode is vulnerable too.
  • It was a true zero-day. F5 confirmed exploitation before releasing hotfixes, and CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, giving federal agencies until Sept. 25.

Shadowserver counts roughly 15,000 internet-exposed BIG-IP APM deployments, about 5,000 of them in North America. Earlier in September, separate reporting described attackers breaching BIG-IP APM devices to install a Linux rootkit. F5 products have been a steady target: CISA has flagged eight actively exploited F5 flaws since 2021, four of them used in ransomware attacks.

Only deployments with an OAuth Authorization Server profile are affected. Systems using APM purely as an OAuth client or resource server are not.

Why it matters for Texas institutions

Large universities, health systems and state agencies across Texas rely on BIG-IP for load balancing, remote access and identity federation. An identity gateway is about the highest-value target on a network: whoever controls it can watch logins, mint tokens and reach the applications behind it.

Because these appliances are maintained by network teams on their own patch schedule, emergency hotfixes can lag behind. And appliances like this rarely run endpoint protection, so a compromise can go unseen.

What your institution should do

  • Check your configuration. Determine whether any virtual server combines an APM access policy with an OAuth Authorization Server profile.
  • Apply F5's hotfix now. Fixes are available for the 21.x, 17.5.x and 17.1.x branches.
  • Use the iRule if you cannot patch today. F5 published a temporary mitigation through its support portal.
  • Hunt for the indicators. Look for repeated OAuth authentication failures paired with suspicious commands, followed by a TMM SIGABRT crash.
  • If you were exposed, assume compromise. Review the appliance for unexpected files, accounts and outbound connections, and rotate any keys and secrets it holds.

RSOC is here to help

RSOC can identify internet-exposed BIG-IP systems, help check for indicators of compromise and support incident response on edge appliances. Contact rsoc@utexas.edu.

Sources: BleepingComputer · The Hacker News · Field Effect · The Register · daily.dev summary