← All hunts high TLP:CLEAR

F5 BIG-IP APM OAuth RCE Exploitation

An unauthenticated attacker is exploiting a heap-based buffer overflow in F5 BIG-IP APM by sending crafted traffic to virtual servers configured with OAuth profiles to achieve code execution.

Based on research by Rapid7 2026-09-28 11 steps · 3 queries T1190

Brief

Why now

Rapid7 recently published a report on CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM. This vulnerability allows an attacker to execute code on the perimeter by sending crafted traffic to virtual servers configured with OAuth profiles. Because F5 devices sit at the edge of the network and mediate access to internal resources, exploitation provides a direct bridgehead for lateral movement.

How the hunt flows

The hunt begins with a scoping phase to identify susceptible infrastructure. The first query checks vulnerability scan results for active findings associated with CVE-2026-94127. This acts as a gate: if the estate contains no vulnerable F5 appliances, the hunt concludes. If the query returns vulnerable hosts, their identifiers populate the next phases of behavioral analysis.

The second phase uses a parallel fan-out to inspect the data plane. One query analyzes HTTP activity, searching for abnormal requests targeting known OAuth endpoints like /oauth/token or /f5-oauth/authorize. It looks for server errors or unusual source IPs that suggest exploitation attempts. Simultaneously, another query baselines outbound network connections from the appliances. It identifies rare external destinations that do not match the standard traffic patterns of the F5 fleet, which often indicates a successful shell callback or data exfiltration.

In the final phase, an analyst synthesizes these signals. The triage process looks for the intersection of a vulnerable host, suspicious OAuth traffic, and rare outbound egress. If the evidence suggests compromise, the hunt provides instructions to isolate the appliance and perform a manual review of system logs for memory errors or process crashes.

What the hunt cannot see

This hunt has two primary blind spots. First, it relies on current vulnerability scan data; an unmanaged or newly deployed F5 appliance missing from the inventory will not trigger the scoping gate. Second, the behavioral analysis requires visibility into the HTTP data plane. If the environment does not capture decrypted HTTP traffic logs including URL paths and query parameters, the hunt cannot identify the specific crafted traffic used in the exploit.

Steps

  1. Identify Vulnerable F5 Instances

    Query · scoping

    Identify any F5 appliances in the inventory that have an active vulnerability finding for CVE-2026-94127.

    reads hb_vulnerability_findingsql
    SELECT resource_uid, cve_uid, severity, status, collected_at FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed' AND collected_at >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Rows identify appliances by resource_uid that are susceptible to the exploit. Silence proves absence of scanned vulnerable instances for the given window.

  2. Assess Vulnerability Lead

    Agent triage

    Evaluate the risk from the lead query to decide if behavioral investigation is warranted.

  3. Gate on Vulnerability Status

    Decision

    Route the hunt based on the presence of vulnerable systems.

  4. Analyze OAuth HTTP Traffic

    Query · triage

    Search for abnormal HTTP requests targeting OAuth endpoints on vulnerable F5 appliances.

    reads hb_http_activitysql
    SELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{oauth_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_path) LIKE '%/oauth%' OR LOWER(url_path) LIKE '%/f5-oauth%') AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Clusters of requests to OAuth endpoints, especially those resulting in server errors or originating from unexpected external IPs. Silence means no suspicious OAuth traffic was recorded.

  5. Baseline Rare Outbound Connections

    Query · baseline

    Identify rare outbound destinations from the appliance data plane which could indicate RCE impact.

    reads hb_network_connectionsql
    SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND direction = 'outbound' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING hosts <= 3 ORDER BY hosts ASC

    What a hit looks like. Individual appliances connecting to unique external IP/port pairs not seen across the rest of the F5 fleet. Silence implies the appliances are following standard traffic patterns.

  6. Triage Exploitation Evidence

    Agent triage

    Synthesize the vulnerability status, suspicious traffic, and rare network egress into a high-confidence verdict.

  7. Route on Exploitation Verdict

    Decision

    Decide whether to isolate the appliance or perform further manual review based on the triage verdict.

  8. Isolate F5 Appliance

    Response action

    Sever the network path for the compromised appliance to prevent lateral movement or exfiltration.

  9. Review Appliance Logs and Configuration

    Analyst task

    Manually verify the presence of a vulnerable configuration (APM Access Policy + OAuth Profile) and check for process-level evidence of exploitation.

  10. Final Close-out

    Analyst task

    Ensure vulnerable but unexploited systems are patched and document the hunt results.

Coverage

Scenario coverage

StageCoveredHow, or why not
Identification of Vulnerable F5 BIG-IP Instances
T1190
Yes vulnerability-lead
Unauthenticated RCE via Crafted OAuth Traffic
T1190
Yes http-traffic-analysis
Post-Exploitation Network Activity
T1190
Yes outbound-connection-baseline

Blind spots

  • Needs recent vulnerability scan against network appliances. A newly deployed or unmanaged F5 appliance may not appear in hb_vulnerability_finding, causing the hunt to terminate early. It would answer Are all F5 devices currently being scanned by vulnerability management tools?.
  • Needs decrypted HTTP traffic logs from the F5 data plane. If only high-level flow data is available without HTTP-level detail, the crafted traffic required for exploitation cannot be identified. It would answer Does the environment capture the URL query parameters and full paths of traffic reaching the APM?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
cve_idstringCVE-2026-94127Target CVE identifier for F5 BIG-IP APM.
lookback_daysnumber14Days of history to examine for vulnerability findings and behavioral traffic.
oauth_pathslist[path]/oauth/token, /oauth/authorize, /f5-oauth/token, /f5-oauth/authorizeStandard OAuth paths for BIG-IP APM likely to be targeted by exploitation traffic.
scope_hostslist[host]—Specific hostnames identified as vulnerable to focus the behavioral analysis.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Network telemetrynetworknetwork
Web server / proxy logssiemnetwork

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: "A standard detection rule would only alert on the presence of a CVE finding.\
  \ This hunt combines vulnerability state with behavioral analysis of the data plane\u2014\
  HTTP path anomalies and outbound connection prevalence\u2014to find active exploitation\
  \ that vulnerability scanners cannot see."
blind_spots:
- id: missing-vulnerability-data
  question: Are all F5 devices currently being scanned by vulnerability management
    tools?
  requires: recent vulnerability scan against network appliances
  risk: A newly deployed or unmanaged F5 appliance may not appear in hb_vulnerability_finding,
    causing the hunt to terminate early.
  stage: vulnerability-assessment-f5
- id: incomplete-appliance-telemetry
  question: Does the environment capture the URL query parameters and full paths of
    traffic reaching the APM?
  requires: decrypted HTTP traffic logs from the F5 data plane
  risk: If only high-level flow data is available without HTTP-level detail, the crafted
    traffic required for exploitation cannot be identified.
  stage: exploit-crafted-traffic-oauth
coverage:
- stage: vulnerability-assessment-f5
  status: covered
  steps:
  - vulnerability-lead
- stage: exploit-crafted-traffic-oauth
  status: covered
  steps:
  - http-traffic-analysis
- stage: post-exploit-network-activity
  status: covered
  steps:
  - outbound-connection-baseline
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: CVE-2026-94127 allows unauthenticated RCE on the perimeter. F5 BIG-IP
    systems are critical infrastructure that mediate access to internal resources;
    a single compromise provides a bridgehead into the entire internal network.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An unauthenticated attacker is exploiting a heap-based buffer overflow
  in F5 BIG-IP APM by sending crafted traffic to virtual servers configured with OAuth
  profiles to achieve code execution.
labels:
- hunt
- attack.t1190
name: F5 BIG-IP APM OAuth RCE Exploitation
parameters:
  cve_id:
    default: CVE-2026-94127
    description: Target CVE identifier for F5 BIG-IP APM.
    from:
      kind: article
      observed: '2026-09-23'
      ref: rapid7
    type: string
  lookback_days:
    default: '14'
    description: Days of history to examine for vulnerability findings and behavioral
      traffic.
    type: number
  oauth_paths:
    default:
    - /oauth/token
    - /oauth/authorize
    - /f5-oauth/token
    - /f5-oauth/authorize
    description: Standard OAuth paths for BIG-IP APM likely to be targeted by exploitation
      traffic.
    type: list[path]
  scope_hosts:
    default: []
    description: Specific hostnames identified as vulnerable to focus the behavioral
      analysis.
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: Start with internet-facing F5 BIG-IP appliances. Use vulnerability scanner
  data (Wiz, Inspector) to quickly narrow down to devices missing the September 2026
  hotfixes.
references:
- name: "Rapid7 \u2014 CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM"
  url: https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm
related:
- hunt: f5-tmui-control-plane-rce
  reason: This hunt focuses on the APM data plane; exploitation of the TMUI management
    interface is a separate attack surface.
  relation: sibling
scenario:
  stages:
  - name: Identification of Vulnerable F5 BIG-IP Instances
    observables:
    - CVE-2026-94127
    - BIG-IP 21.1.0
    - BIG-IP 17.5.0
    - BIG-IP 17.1.0
    - F5 BIG-IP APM
    - OAuth profile configured
    - APM access policy configured
    slug: vulnerability-assessment-f5
    tactic: initial-access
    techniques:
    - T1190
  - name: Unauthenticated RCE via Crafted OAuth Traffic
    observables:
    - specifically crafted traffic
    - unauthenticated network access to virtual server
    - heap-based buffer overflow attack
    slug: exploit-crafted-traffic-oauth
    tactic: initial-access
    techniques:
    - T1190
  - name: Post-Exploitation Network Activity
    observables:
    - remote code execution
    - outbound network connections from BIG-IP data plane
    slug: post-exploit-network-activity
    tactic: execution
    techniques:
    - T1190
  summary: An unauthenticated attacker can exploit a critical heap-based buffer overflow
    in F5 BIG-IP Access Policy Manager (APM) via CVE-2026-94127. Exploitation requires
    a virtual server with both an APM access policy and an OAuth profile and allows
    for remote code execution (RCE) on the device's data plane.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# F5 BIG-IP APM OAuth RCE Exploitation

This hunt targets the exploitation of CVE-2026-94127, a critical RCE vulnerability in F5 BIG-IP APM. The vulnerability requires a specific configuration: a virtual server with both an APM access policy and an OAuth profile. This hunt uses a gated flow, first identifying vulnerable F5 appliances via vulnerability scan results. If vulnerable hosts are present, it performs a fan-out to examine HTTP traffic for OAuth-related anomalies and identifies rare outbound network connections from those appliances that may indicate a successful shell callback or data exfiltration.

## vulnerability-lead
<!-- Identify Vulnerable F5 Instances -->
Identify any F5 appliances in the inventory that have an active vulnerability finding for CVE-2026-94127.

```sqlite target=endpoint role=scoping params=(cve_id=cve_id, lookback_days=lookback_days)
~~~yaml
expected: Rows identify appliances by resource_uid that are susceptible to the exploit.
  Silence proves absence of scanned vulnerable instances for the given window.
reads:
- resource_uid
- cve_uid
- severity
- status
- collected_at
silence: evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT resource_uid, cve_uid, severity, status, collected_at FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed' AND collected_at >= datetime('now', '-{{lookback_days}} days')
```

## assess-vulnerability-risk
<!-- Assess Vulnerability Lead -->
```agent target=hunter
cite: required
context:
- vulnerability-lead
max_iterations: 3
objective: Determine if any F5 devices are confirmed vulnerable and list their identifiers
  for follow-up analysis.
success_criteria: A list of potentially compromised hosts or a clean bill of health.
tools:
- endpoint
- network
- web
```

## gate-on-vulnerability
<!-- Gate on Vulnerability Status -->
if~: "the assess-vulnerability-risk verdict identifies at least one vulnerable appliance" (confidence: high, judge=hunter)
then: → investigate-behavior
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: missing-vulnerability-data)
else: → final-close-out

## investigate-behavior
<!-- Investigate Appliance Behavior -->
parallel:
- → http-traffic-analysis
- → outbound-connection-baseline
join: → triage-exploitation

## http-traffic-analysis
<!-- Analyze OAuth HTTP Traffic -->
Search for abnormal HTTP requests targeting OAuth endpoints on vulnerable F5 appliances.

```sqlite target=web role=triage params=(lookback_days=lookback_days, oauth_paths=oauth_paths, scope_hosts=scope_hosts)
~~~yaml
expected: Clusters of requests to OAuth endpoints, especially those resulting in server
  errors or originating from unexpected external IPs. Silence means no suspicious
  OAuth traffic was recorded.
reads:
- device_hostname
- src_endpoint_ip
- url_path
- url_query
- status_code
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{oauth_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_path) LIKE '%/oauth%' OR LOWER(url_path) LIKE '%/f5-oauth%') AND time >= datetime('now', '-{{lookback_days}} days')
```

## outbound-connection-baseline
<!-- Baseline Rare Outbound Connections -->
Identify rare outbound destinations from the appliance data plane which could indicate RCE impact.

```sqlite target=network role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Individual appliances connecting to unique external IP/port pairs not seen
  across the rest of the F5 fleet. Silence implies the appliances are following standard
  traffic patterns.
prevalence:
  by: device_hostname
  key:
  - dst_endpoint_ip
  - dst_endpoint_port
  rare_below: 3
reads:
- dst_endpoint_ip
- dst_endpoint_port
- device_hostname
- direction
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND direction = 'outbound' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING hosts <= 3 ORDER BY hosts ASC
```

## triage-exploitation
<!-- Triage Exploitation Evidence -->
```agent target=hunter
cite: required
context:
- assess-vulnerability-risk
- http-traffic-analysis
- outbound-connection-baseline
max_iterations: 5
objective: Determine if any vulnerable F5 instance shows signs of active exploitation
  citing specific rows from the HTTP and network connections queries.
success_criteria: A per-host verdict citing specific evidence from all context steps.
tools:
- endpoint
- network
- web
```

## route-on-evidence
<!-- Route on Exploitation Verdict -->
if~: "the triage-exploitation verdict is malicious for at least one vulnerable host" (confidence: high, judge=hunter)
then: → isolate-appliance
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: incomplete-appliance-telemetry)
else: → final-close-out

## isolate-appliance
<!-- Isolate F5 Appliance -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the compromised F5 BIG-IP appliance at the switch or network security group level. Disable the affected APM virtual servers immediately.
```
→ analyst-review

## analyst-review
<!-- Review Appliance Logs and Configuration -->
```manual target=analyst
Review the BIG-IP configuration to confirm if an APM Access Policy and an OAuth Profile are assigned to the target virtual server. Check /var/log/tmm and /var/log/apm for SIGSEGV crashes or memory errors that correspond with the timing of suspicious traffic.
```
→ final-close-out

## final-close-out
<!-- Final Close-out -->
```manual target=analyst
Document the findings. For any appliance identified as vulnerable but not exploited, apply the F5 hotfix immediately. If exploitation was confirmed, initiate the Incident Response protocol.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.