---
analysis: "A standard detection rule would only alert on the presence of a CVE finding.\
  \ This hunt combines vulnerability state with behavioral analysis of the data plane\u2014\
  HTTP path anomalies and outbound connection prevalence\u2014to find active exploitation\
  \ that vulnerability scanners cannot see."
blind_spots:
- id: missing-vulnerability-data
  question: Are all F5 devices currently being scanned by vulnerability management
    tools?
  requires: recent vulnerability scan against network appliances
  risk: A newly deployed or unmanaged F5 appliance may not appear in hb_vulnerability_finding,
    causing the hunt to terminate early.
  stage: vulnerability-assessment-f5
- id: incomplete-appliance-telemetry
  question: Does the environment capture the URL query parameters and full paths of
    traffic reaching the APM?
  requires: decrypted HTTP traffic logs from the F5 data plane
  risk: If only high-level flow data is available without HTTP-level detail, the crafted
    traffic required for exploitation cannot be identified.
  stage: exploit-crafted-traffic-oauth
coverage:
- stage: vulnerability-assessment-f5
  status: covered
  steps:
  - vulnerability-lead
- stage: exploit-crafted-traffic-oauth
  status: covered
  steps:
  - http-traffic-analysis
- stage: post-exploit-network-activity
  status: covered
  steps:
  - outbound-connection-baseline
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: CVE-2026-94127 allows unauthenticated RCE on the perimeter. F5 BIG-IP
    systems are critical infrastructure that mediate access to internal resources;
    a single compromise provides a bridgehead into the entire internal network.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An unauthenticated attacker is exploiting a heap-based buffer overflow
  in F5 BIG-IP APM by sending crafted traffic to virtual servers configured with OAuth
  profiles to achieve code execution.
labels:
- hunt
- attack.t1190
name: F5 BIG-IP APM OAuth RCE Exploitation
parameters:
  cve_id:
    default: CVE-2026-94127
    description: Target CVE identifier for F5 BIG-IP APM.
    from:
      kind: article
      observed: '2026-09-23'
      ref: rapid7
    type: string
  lookback_days:
    default: '14'
    description: Days of history to examine for vulnerability findings and behavioral
      traffic.
    type: number
  oauth_paths:
    default:
    - /oauth/token
    - /oauth/authorize
    - /f5-oauth/token
    - /f5-oauth/authorize
    description: Standard OAuth paths for BIG-IP APM likely to be targeted by exploitation
      traffic.
    type: list[path]
  scope_hosts:
    default: []
    description: Specific hostnames identified as vulnerable to focus the behavioral
      analysis.
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: Start with internet-facing F5 BIG-IP appliances. Use vulnerability scanner
  data (Wiz, Inspector) to quickly narrow down to devices missing the September 2026
  hotfixes.
references:
- name: "Rapid7 \u2014 CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM"
  url: https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm
related:
- hunt: f5-tmui-control-plane-rce
  reason: This hunt focuses on the APM data plane; exploitation of the TMUI management
    interface is a separate attack surface.
  relation: sibling
scenario:
  stages:
  - name: Identification of Vulnerable F5 BIG-IP Instances
    observables:
    - CVE-2026-94127
    - BIG-IP 21.1.0
    - BIG-IP 17.5.0
    - BIG-IP 17.1.0
    - F5 BIG-IP APM
    - OAuth profile configured
    - APM access policy configured
    slug: vulnerability-assessment-f5
    tactic: initial-access
    techniques:
    - T1190
  - name: Unauthenticated RCE via Crafted OAuth Traffic
    observables:
    - specifically crafted traffic
    - unauthenticated network access to virtual server
    - heap-based buffer overflow attack
    slug: exploit-crafted-traffic-oauth
    tactic: initial-access
    techniques:
    - T1190
  - name: Post-Exploitation Network Activity
    observables:
    - remote code execution
    - outbound network connections from BIG-IP data plane
    slug: post-exploit-network-activity
    tactic: execution
    techniques:
    - T1190
  summary: An unauthenticated attacker can exploit a critical heap-based buffer overflow
    in F5 BIG-IP Access Policy Manager (APM) via CVE-2026-94127. Exploitation requires
    a virtual server with both an APM access policy and an OAuth profile and allows
    for remote code execution (RCE) on the device's data plane.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  network:
    category: network
    name: Network telemetry
    telemetry:
    - network
  web:
    category: siem
    name: Web server / proxy logs
    telemetry:
    - network
tlp: clear
type: investigation
---


# F5 BIG-IP APM OAuth RCE Exploitation

This hunt targets the exploitation of CVE-2026-94127, a critical RCE vulnerability in F5 BIG-IP APM. The vulnerability requires a specific configuration: a virtual server with both an APM access policy and an OAuth profile. This hunt uses a gated flow, first identifying vulnerable F5 appliances via vulnerability scan results. If vulnerable hosts are present, it performs a fan-out to examine HTTP traffic for OAuth-related anomalies and identifies rare outbound network connections from those appliances that may indicate a successful shell callback or data exfiltration.

## vulnerability-lead
<!-- Identify Vulnerable F5 Instances -->
Identify any F5 appliances in the inventory that have an active vulnerability finding for CVE-2026-94127.

```sqlite target=endpoint role=scoping params=(cve_id=cve_id, lookback_days=lookback_days)
~~~yaml
expected: Rows identify appliances by resource_uid that are susceptible to the exploit.
  Silence proves absence of scanned vulnerable instances for the given window.
reads:
- resource_uid
- cve_uid
- severity
- status
- collected_at
silence: evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT resource_uid, cve_uid, severity, status, collected_at FROM hb_vulnerability_finding WHERE cve_uid = '{{cve_id}}' AND status != 'suppressed' AND collected_at >= datetime('now', '-{{lookback_days}} days')
```

## assess-vulnerability-risk
<!-- Assess Vulnerability Lead -->
```agent target=hunter
cite: required
context:
- vulnerability-lead
max_iterations: 3
objective: Determine if any F5 devices are confirmed vulnerable and list their identifiers
  for follow-up analysis.
success_criteria: A list of potentially compromised hosts or a clean bill of health.
tools:
- endpoint
- network
- web
```

## gate-on-vulnerability
<!-- Gate on Vulnerability Status -->
if~: "the assess-vulnerability-risk verdict identifies at least one vulnerable appliance" (confidence: high, judge=hunter)
then: → investigate-behavior
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: missing-vulnerability-data)
else: → final-close-out

## investigate-behavior
<!-- Investigate Appliance Behavior -->
parallel:
- → http-traffic-analysis
- → outbound-connection-baseline
join: → triage-exploitation

## http-traffic-analysis
<!-- Analyze OAuth HTTP Traffic -->
Search for abnormal HTTP requests targeting OAuth endpoints on vulnerable F5 appliances.

```sqlite target=web role=triage params=(lookback_days=lookback_days, oauth_paths=oauth_paths, scope_hosts=scope_hosts)
~~~yaml
expected: Clusters of requests to OAuth endpoints, especially those resulting in server
  errors or originating from unexpected external IPs. Silence means no suspicious
  OAuth traffic was recorded.
reads:
- device_hostname
- src_endpoint_ip
- url_path
- url_query
- status_code
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, src_endpoint_ip, url_path, url_query, status_code, time FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{oauth_paths}}' || ',', ',' || LOWER(url_path) || ',') > 0 OR LOWER(url_path) LIKE '%/oauth%' OR LOWER(url_path) LIKE '%/f5-oauth%') AND time >= datetime('now', '-{{lookback_days}} days')
```

## outbound-connection-baseline
<!-- Baseline Rare Outbound Connections -->
Identify rare outbound destinations from the appliance data plane which could indicate RCE impact.

```sqlite target=network role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Individual appliances connecting to unique external IP/port pairs not seen
  across the rest of the F5 fleet. Silence implies the appliances are following standard
  traffic patterns.
prevalence:
  by: device_hostname
  key:
  - dst_endpoint_ip
  - dst_endpoint_port
  rare_below: 3
reads:
- dst_endpoint_ip
- dst_endpoint_port
- device_hostname
- direction
- time
silence: not_evidence_of_absence
source: hb_network_connection
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT dst_endpoint_ip, dst_endpoint_port, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_network_connection WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND direction = 'outbound' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY dst_endpoint_ip, dst_endpoint_port HAVING hosts <= 3 ORDER BY hosts ASC
```

## triage-exploitation
<!-- Triage Exploitation Evidence -->
```agent target=hunter
cite: required
context:
- assess-vulnerability-risk
- http-traffic-analysis
- outbound-connection-baseline
max_iterations: 5
objective: Determine if any vulnerable F5 instance shows signs of active exploitation
  citing specific rows from the HTTP and network connections queries.
success_criteria: A per-host verdict citing specific evidence from all context steps.
tools:
- endpoint
- network
- web
```

## route-on-evidence
<!-- Route on Exploitation Verdict -->
if~: "the triage-exploitation verdict is malicious for at least one vulnerable host" (confidence: high, judge=hunter)
then: → isolate-appliance
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: incomplete-appliance-telemetry)
else: → final-close-out

## isolate-appliance
<!-- Isolate F5 Appliance -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the compromised F5 BIG-IP appliance at the switch or network security group level. Disable the affected APM virtual servers immediately.
```
→ analyst-review

## analyst-review
<!-- Review Appliance Logs and Configuration -->
```manual target=analyst
Review the BIG-IP configuration to confirm if an APM Access Policy and an OAuth Profile are assigned to the target virtual server. Check /var/log/tmm and /var/log/apm for SIGSEGV crashes or memory errors that correspond with the timing of suspicious traffic.
```
→ final-close-out

## final-close-out
<!-- Final Close-out -->
```manual target=analyst
Document the findings. For any appliance identified as vulnerable but not exploited, apply the F5 hotfix immediately. If exploitation was confirmed, initiate the Incident Response protocol.
```
→ end
