Identity is not a soft layer. On an F5 BIG-IP Access Policy Manager that issues OAuth tokens, it is the attack surface.
On September 22 F5 disclosed CVE-2026-94127 — a heap-based buffer overflow that lets an unauthenticated attacker reach remote code execution when APM runs as an OAuth authorization server on the same virtual server as an APM access policy. The Hacker News (Sep 23), citing F5, puts CVSS at 9.8 (v3.1) and 9.3 (v4.0). Appliance mode is still vulnerable. Limiting the management interface does nothing — the malicious traffic lands on the virtual server itself.
CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day and set a September 25 due date for federal civilian agencies. That is a three-day shot clock on the identity plane. The Canadian Centre for Cyber Security published AL26-022 on Sep 22 and confirmed F5’s statement that the bug is exploited in the wild. CIS Advisory 2026-098 points operators to F5 article K000162605.
Who is in scope — print the vendor narrowing, not the rumor. F5 updated the CVE record at 00:45 UTC on September 23: the condition is the authorization server role. Systems that use APM only as an OAuth client or resource server, with no authorization-server profiles, are not affected. Earlier CISA/CERT-EU wording was broader (access policy + OAuth profile on a VS). Prefer F5’s revised condition when you inventory.
Hotfix first. Per The Hacker News’ table of F5 engineering builds: 21.1 → Hotfix-BIGIP-21.1.0.2.0.30.22-ENG; 17.5.0–17.5.1 → Hotfix-BIGIP-17.5.1.9.0.160.12-ENG; 17.1.0–17.1.3 → Hotfix-BIGIP-17.1.3.5.0.41.14-ENG. If you cannot install immediately, F5 offers an iRule mitigation via a support ticket. CISA’s guidance, as reported by THN: apply the iRule first to allow proactive forensic triage, then install the final vendor patch as soon as possible. End-of-Technical-Support branches were not evaluated — unknown is not safe.
Compromise signals F5 listed (via CERT-EU / THN): repeated failed UserInfo requests in /var/log/apm (“The access token is invalid”), especially 10+ from one IP in a short window; unexplained rise in total_failed on tmctl global_oauth_stat; suspicious audit-log commands around those failures; TMM SIGABRT after a loop. Installing the hotfix does not, per F5/CISA/CERT-EU, prove prior access is gone.
Same-week KEV color only: CyberMerge’s desk already tracked parallel CISA KEV adds for Check Point management (CVE-2026-93616) and Arista VeloCloud (CVE-2026-93952). The pattern is not “another CVE.” It is control-plane and access-plane products becoming force multipliers when they sit on the path every identity token crosses.
POV: boards that treat APM as plumbing will miss the point. An OAuth authorization server whose token endpoint is internet-reachable is a crown jewel with a CVSS that says so. Patch the hotfix. Stage the iRule if you cannot. Preserve forensics before you wipe. Exploit volume and APT names: Undisclosed. F5’s CVE text and CISA’s KEV entry have published neither.
Underwrite sheet — sourced only: CVE-2026-94127 heap overflow / unauth RCE on APM OAuth authorization server (F5 / THN / CCCS / CIS); CVSS 9.8 / 9.3 (THN citing F5); CISA KEV Sep 22, federal due Sep 25 (THN); AL26-022 Sep 22 (CCCS); K000162605 (F5 via CIS); branch hotfixes + iRule (THN/CCCS); exploit counts and attacker attribution Undisclosed. Identity plane as force multiplier — hotfix vs iRule, not press theater.
