

Affected Environment
F5 BIG-IP Access Policy Manager module across versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3.
Threat Overview
A critical zero-day enables unauthenticated remote code execution when the APM access policy uses an OAuth profile.
Exposure Timeline
Disclosed and added to CISA's KEV catalog in September 2026; actively exploited before patches were widely applied.
Attack Surface
Data plane traffic reaching virtual servers configured with a BIG-IP APM access policy and OAuth profile.
Technical Root Cause
Malicious traffic against the APM access policy and OAuth profile triggers unauthenticated remote code execution.
Exploitation Pathway
Attacker sends crafted traffic to a vulnerable virtual server, triggering RCE and gaining full system control.
Operational Impact
Full control of the affected system, enabling installation of programs, data manipulation, or new accounts.
Strategic Impact
Critical for all sectors given BIG-IP APM's widespread use in identity and network access control.
Required Mitigation
Apply F5's iRule mitigation or update to a fixed BIG-IP release immediately after testing.
Incident Response Guidance
Review var log apm for repeated OAuth failures and investigate TMM core files near those timestamps.
References
F5 Security Advisory K000162605, BleepingComputer.
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




