Back

CRITICAL KEV

BIG-IP APM OAuth vulnerability

Published Sep 22, 2026 ·Due Sep 25, 2026

Description

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.

Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

Remediation

Vendor solution

An iRule is available upon request. Open a ticket with F5 support to request this.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner f5
Published Sep 22, 2026
Updated Sep 23, 2026
Reserved Sep 20, 2026
CISA Vulnrichment
Updated Sep 22, 2026
NVD
Status Analyzed
Modified Sep 23, 2026
Red Hat
Severity n/a
Public date n/a