Attackers are taking advantage of a significant vulnerability in F5's BIG-IP Access Policy Manager (APM), allowing them to execute code on the system without needing authentication This article explores exploited vulnerabilities kev. . The vulnerability, CVE-2026-94127, impacts systems where APM acts as an OAuth authorization server, granting access tokens to applications.
An insecure setup includes an APM access policy and an OAuth authorization server profile on the same virtual server, which hosts the BIG-IP address that handles OAuth traffic. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 22. CERT-EU advises preserving forensic evidence first, applying the hotfix, checking for signs of compromise, and starting incident response if any are found.
CISA told agencies to apply the iRule first "to allow for proactive forensic triage," and then to "install the final vendor patch as soon as possible." ### Checking for Compromise The signs indicate that these are F5 devices, as per CERT-EU's advisory. The sequence leading to a human review is two OAuth authentication failures, followed by suspicious commands, and then a TMM SIGABRT shortly after.
APM log: Multiple failed UserInfo requests in /var/log/apm, with error "Access token invalid." Check for 10 or more requests from a single IP within a short timeframe. F5 has experienced TMM entering a loop, leading to SOD daemon sending a SIGABRT.




![Top 10 Best Decentralized Identity Solutions in 2026 [Ranked & Scored]](http://cybersecuritynews.com/wp-content/uploads/2026/09/Best-Decentralized-Identity-Solutions-1.webp)







