F5 BIG-IP APM OAuth RCE Exploitation
An unauthenticated attacker is exploiting a heap-based buffer overflow in F5 BIG-IP APM by sending crafted traffic to virtual servers configured with OAuth profiles to achieve code execution.
Based on research by Rapid7 2026-09-28 11 steps · 3 queries T1190
Brief
Why now
Rapid7 recently published a report on CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM. This vulnerability allows an attacker to execute code on the perimeter by sending crafted traffic to virtual servers configured with OAuth profiles. Because F5 devices sit at the edge of the network and mediate access to internal resources, exploitation provides a direct bridgehead for lateral movement.
How the hunt flows
The hunt begins with a scoping phase to identify susceptible infrastructure. The first query checks vulnerability scan results for active findings associated with CVE-2026-94127. This acts as a gate: if the estate contains no vulnerable F5 appliances, the hunt concludes. If the query returns vulnerable hosts, their identifiers populate the next phases of behavioral analysis.
The second phase uses a parallel fan-out to inspect the data plane. One query analyzes HTTP activity, searching for abnormal requests targeting known OAuth endpoints like /oauth/token or /f5-oauth/authorize. It looks for server errors or unusual source IPs that suggest exploitation attempts. Simultaneously, another query baselines outbound network connections from the appliances. It identifies rare external destinations that do not match the standard traffic patterns of the F5 fleet, which often indicates a successful shell callback or data exfiltration.
In the final phase, an analyst synthesizes these signals. The triage process looks for the intersection of a vulnerable host, suspicious OAuth traffic, and rare outbound egress. If the evidence suggests compromise, the hunt provides instructions to isolate the appliance and perform a manual review of system logs for memory errors or process crashes.
What the hunt cannot see
This hunt has two primary blind spots. First, it relies on current vulnerability scan data; an unmanaged or newly deployed F5 appliance missing from the inventory will not trigger the scoping gate. Second, the behavioral analysis requires visibility into the HTTP data plane. If the environment does not capture decrypted HTTP traffic logs including URL paths and query parameters, the hunt cannot identify the specific crafted traffic used in the exploit.
Steps
-
Identify Vulnerable F5 Instances
Query · scopingIdentify any F5 appliances in the inventory that have an active vulnerability finding for CVE-2026-94127.
reads hb_vulnerability_findingsqlSELECT resource_uid, cve_uid, severity, status, collected_at FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed' AND collected_at >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Rows identify appliances by resource_uid that are susceptible to the exploit. Silence proves absence of scanned vulnerable instances for the given window.
-
Assess Vulnerability Lead
Agent triageEvaluate the risk from the lead query to decide if behavioral investigation is warranted.
-
Gate on Vulnerability Status
DecisionRoute the hunt based on the presence of vulnerable systems.
-
Analyze OAuth HTTP Traffic
Query · triageSearch for abnormal HTTP requests targeting OAuth endpoints on vulnerable F5 appliances.
reads hb_http_activitysqlSELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{oauth_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_path) LIKE '%/oauth%' OR LOWER(url_path) LIKE '%/f5-oauth%') AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Clusters of requests to OAuth endpoints, especially those resulting in server errors or originating from unexpected external IPs. Silence means no suspicious OAuth traffic was recorded.
-
Baseline Rare Outbound Connections
Query · baselineIdentify rare outbound destinations from the appliance data plane which could indicate RCE impact.
reads hb_network_connectionsqlSELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND direction = 'outbound' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING hosts <= 3 ORDER BY hosts ASCWhat a hit looks like. Individual appliances connecting to unique external IP/port pairs not seen across the rest of the F5 fleet. Silence implies the appliances are following standard traffic patterns.
-
Triage Exploitation Evidence
Agent triageSynthesize the vulnerability status, suspicious traffic, and rare network egress into a high-confidence verdict.
-
Route on Exploitation Verdict
DecisionDecide whether to isolate the appliance or perform further manual review based on the triage verdict.
-
Isolate F5 Appliance
Response actionSever the network path for the compromised appliance to prevent lateral movement or exfiltration.
-
Review Appliance Logs and Configuration
Analyst taskManually verify the presence of a vulnerable configuration (APM Access Policy + OAuth Profile) and check for process-level evidence of exploitation.
-
Final Close-out
Analyst taskEnsure vulnerable but unexploited systems are patched and document the hunt results.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Identification of Vulnerable F5 BIG-IP Instances T1190 |
Yes | vulnerability-lead |
| Unauthenticated RCE via Crafted OAuth Traffic T1190 |
Yes | http-traffic-analysis |
| Post-Exploitation Network Activity T1190 |
Yes | outbound-connection-baseline |
Blind spots
- Needs recent vulnerability scan against network appliances. A newly deployed or unmanaged F5 appliance may not appear in hb_vulnerability_finding, causing the hunt to terminate early. It would answer Are all F5 devices currently being scanned by vulnerability management tools?.
- Needs decrypted HTTP traffic logs from the F5 data plane. If only high-level flow data is available without HTTP-level detail, the crafted traffic required for exploitation cannot be identified. It would answer Does the environment capture the URL query parameters and full paths of traffic reaching the APM?.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
cve_id | string | CVE-2026-94127 | Target CVE identifier for F5 BIG-IP APM. |
lookback_days | number | 14 | Days of history to examine for vulnerability findings and behavioral traffic. |
oauth_paths | list[path] | /oauth/token, /oauth/authorize, /f5-oauth/token, /f5-oauth/authorize | Standard OAuth paths for BIG-IP APM likely to be targeted by exploitation traffic. |
scope_hosts | list[host] | — | Specific hostnames identified as vulnerable to focus the behavioral analysis. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Network telemetry | network | network |
| Web server / proxy logs | siem | network |
Source
---
analysis: "A standard detection rule would only alert on the presence of a CVE finding.\
\ This hunt combines vulnerability state with behavioral analysis of the data plane\u2014\
HTTP path anomalies and outbound connection prevalence\u2014to find active exploitation\
\ that vulnerability scanners cannot see."
blind_spots:
- id: missing-vulnerability-data
question: Are all F5 devices currently being scanned by vulnerability management
tools?
requires: recent vulnerability scan against network appliances
risk: A newly deployed or unmanaged F5 appliance may not appear in hb_vulnerability_finding,
causing the hunt to terminate early.
stage: vulnerability-assessment-f5
- id: incomplete-appliance-telemetry
question: Does the environment capture the URL query parameters and full paths of
traffic reaching the APM?
requires: decrypted HTTP traffic logs from the F5 data plane
risk: If only high-level flow data is available without HTTP-level detail, the crafted
traffic required for exploitation cannot be identified.
stage: exploit-crafted-traffic-oauth
coverage:
- stage: vulnerability-assessment-f5
status: covered
steps:
- vulnerability-lead
- stage: exploit-crafted-traffic-oauth
status: covered
steps:
- http-traffic-analysis
- stage: post-exploit-network-activity
status: covered
steps:
- outbound-connection-baseline
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: keep-as-periodic-hunt
justification: CVE-2026-94127 allows unauthenticated RCE on the perimeter. F5 BIG-IP
systems are critical infrastructure that mediate access to internal resources;
a single compromise provides a bridgehead into the entire internal network.
methodology: model-assisted
trigger: intel-report
hypothesis: An unauthenticated attacker is exploiting a heap-based buffer overflow
in F5 BIG-IP APM by sending crafted traffic to virtual servers configured with OAuth
profiles to achieve code execution.
labels:
- hunt
- attack.t1190
name: F5 BIG-IP APM OAuth RCE Exploitation
parameters:
cve_id:
default: CVE-2026-94127
description: Target CVE identifier for F5 BIG-IP APM.
from:
kind: article
observed: '2026-09-23'
ref: rapid7
type: string
lookback_days:
default: '14'
description: Days of history to examine for vulnerability findings and behavioral
traffic.
type: number
oauth_paths:
default:
- /oauth/token
- /oauth/authorize
- /f5-oauth/token
- /f5-oauth/authorize
description: Standard OAuth paths for BIG-IP APM likely to be targeted by exploitation
traffic.
type: list[path]
scope_hosts:
default: []
description: Specific hostnames identified as vulnerable to focus the behavioral
analysis.
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm
gates:
- dry-run
- lint
- critic
model: hb_google/gemini-3-flash-preview
rationale: Start with internet-facing F5 BIG-IP appliances. Use vulnerability scanner
data (Wiz, Inspector) to quickly narrow down to devices missing the September 2026
hotfixes.
references:
- name: "Rapid7 \u2014 CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM"
url: https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm
related:
- hunt: f5-tmui-control-plane-rce
reason: This hunt focuses on the APM data plane; exploitation of the TMUI management
interface is a separate attack surface.
relation: sibling
scenario:
stages:
- name: Identification of Vulnerable F5 BIG-IP Instances
observables:
- CVE-2026-94127
- BIG-IP 21.1.0
- BIG-IP 17.5.0
- BIG-IP 17.1.0
- F5 BIG-IP APM
- OAuth profile configured
- APM access policy configured
slug: vulnerability-assessment-f5
tactic: initial-access
techniques:
- T1190
- name: Unauthenticated RCE via Crafted OAuth Traffic
observables:
- specifically crafted traffic
- unauthenticated network access to virtual server
- heap-based buffer overflow attack
slug: exploit-crafted-traffic-oauth
tactic: initial-access
techniques:
- T1190
- name: Post-Exploitation Network Activity
observables:
- remote code execution
- outbound network connections from BIG-IP data plane
slug: post-exploit-network-activity
tactic: execution
techniques:
- T1190
summary: An unauthenticated attacker can exploit a critical heap-based buffer overflow
in F5 BIG-IP Access Policy Manager (APM) via CVE-2026-94127. Exploitation requires
a virtual server with both an APM access policy and an OAuth profile and allows
for remote code execution (RCE) on the device's data plane.
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
network:
category: network
name: Network telemetry
telemetry:
- network
web:
category: siem
name: Web server / proxy logs
telemetry:
- network
tlp: clear
type: investigation
---
# F5 BIG-IP APM OAuth RCE Exploitation
This hunt targets the exploitation of CVE-2026-94127, a critical RCE vulnerability in F5 BIG-IP APM. The vulnerability requires a specific configuration: a virtual server with both an APM access policy and an OAuth profile. This hunt uses a gated flow, first identifying vulnerable F5 appliances via vulnerability scan results. If vulnerable hosts are present, it performs a fan-out to examine HTTP traffic for OAuth-related anomalies and identifies rare outbound network connections from those appliances that may indicate a successful shell callback or data exfiltration.
## vulnerability-lead
<!-- Identify Vulnerable F5 Instances -->
Identify any F5 appliances in the inventory that have an active vulnerability finding for CVE-2026-94127.
```sqlite target=endpoint role=scoping params=(cve_id=cve_id, lookback_days=lookback_days)
~~~yaml
expected: Rows identify appliances by resource_uid that are susceptible to the exploit.
Silence proves absence of scanned vulnerable instances for the given window.
reads:
- resource_uid
- cve_uid
- severity
- status
- collected_at
silence: evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT resource_uid, cve_uid, severity, status, collected_at FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed' AND collected_at >= datetime('now', '-{{lookback_days}} days')
```
## assess-vulnerability-risk
<!-- Assess Vulnerability Lead -->
```agent target=hunter
cite: required
context:
- vulnerability-lead
max_iterations: 3
objective: Determine if any F5 devices are confirmed vulnerable and list their identifiers
for follow-up analysis.
success_criteria: A list of potentially compromised hosts or a clean bill of health.
tools:
- endpoint
- network
- web
```
## gate-on-vulnerability
<!-- Gate on Vulnerability Status -->
if~: "the assess-vulnerability-risk verdict identifies at least one vulnerable appliance" (confidence: high, judge=hunter)
then: → investigate-behavior
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: missing-vulnerability-data)
else: → final-close-out
## investigate-behavior
<!-- Investigate Appliance Behavior -->
parallel:
- → http-traffic-analysis
- → outbound-connection-baseline
join: → triage-exploitation
## http-traffic-analysis
<!-- Analyze OAuth HTTP Traffic -->
Search for abnormal HTTP requests targeting OAuth endpoints on vulnerable F5 appliances.
```sqlite target=web role=triage params=(lookback_days=lookback_days, oauth_paths=oauth_paths, scope_hosts=scope_hosts)
~~~yaml
expected: Clusters of requests to OAuth endpoints, especially those resulting in server
errors or originating from unexpected external IPs. Silence means no suspicious
OAuth traffic was recorded.
reads:
- device_hostname
- src_endpoint_ip
- url_path
- url_query
- status_code
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{oauth_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_path) LIKE '%/oauth%' OR LOWER(url_path) LIKE '%/f5-oauth%') AND time >= datetime('now', '-{{lookback_days}} days')
```
## outbound-connection-baseline
<!-- Baseline Rare Outbound Connections -->
Identify rare outbound destinations from the appliance data plane which could indicate RCE impact.
```sqlite target=network role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: Individual appliances connecting to unique external IP/port pairs not seen
across the rest of the F5 fleet. Silence implies the appliances are following standard
traffic patterns.
prevalence:
by: device_hostname
key:
- dst_endpoint_ip
- dst_endpoint_port
rare_below: 3
reads:
- dst_endpoint_ip
- dst_endpoint_port
- device_hostname
- direction
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND direction = 'outbound' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING hosts <= 3 ORDER BY hosts ASC
```
## triage-exploitation
<!-- Triage Exploitation Evidence -->
```agent target=hunter
cite: required
context:
- assess-vulnerability-risk
- http-traffic-analysis
- outbound-connection-baseline
max_iterations: 5
objective: Determine if any vulnerable F5 instance shows signs of active exploitation
citing specific rows from the HTTP and network connections queries.
success_criteria: A per-host verdict citing specific evidence from all context steps.
tools:
- endpoint
- network
- web
```
## route-on-evidence
<!-- Route on Exploitation Verdict -->
if~: "the triage-exploitation verdict is malicious for at least one vulnerable host" (confidence: high, judge=hunter)
then: → isolate-appliance
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: incomplete-appliance-telemetry)
else: → final-close-out
## isolate-appliance
<!-- Isolate F5 Appliance -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the compromised F5 BIG-IP appliance at the switch or network security group level. Disable the affected APM virtual servers immediately.
```
→ analyst-review
## analyst-review
<!-- Review Appliance Logs and Configuration -->
```manual target=analyst
Review the BIG-IP configuration to confirm if an APM Access Policy and an OAuth Profile are assigned to the target virtual server. Check /var/log/tmm and /var/log/apm for SIGSEGV crashes or memory errors that correspond with the timing of suspicious traffic.
```
→ final-close-out
## final-close-out
<!-- Final Close-out -->
```manual target=analyst
Document the findings. For any appliance identified as vulnerable but not exploited, apply the F5 hotfix immediately. If exploitation was confirmed, initiate the Incident Response protocol.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.