When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
The vulnerability is classified as CWE-121 (stack-based buffer overflow). When an APM access policy is configured on a BIG-IP virtual server, specially crafted malicious network traffic can overflow a stack buffer, leading to control flow hijacking of the process. The attack requires no authentication, user interaction, or special preconditions — an attacker only needs network access to the interface served by the vulnerable virtual server.
An attacker can achieve remote code execution (RCE) on an F5 BIG-IP device, which in practice means complete takeover of the device, including potential access to managed network traffic, user authentication credentials using APM, and internal infrastructure.
Immediately apply patches available from the vendor according to the official F5 article K000156741 (https://my.f5.com/manage/s/article/K000156741). Until the patch is deployed, consider restricting network access to virtual servers with APM configuration to trusted IP addresses only and monitor anomalous traffic directed to these services.
F5 BIG-IP Access Policy Manager (APM) — versions specified in vendor references (versions under technical support); the virtual server must have an APM access policy configured. Versions that have reached end of technical support (EoTS) are not covered by this assessment.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XF5 Big Ip Access Policy Manager
APPF515.1.0 – 15.1.10.8 (excl.)16.1.0 – 16.1.6.1 (excl.)17.1.0 – 17.1.3 (excl.)17.5.0 – 17.5.1.3 (excl.)
CISA KEV — detailsi
- Vendori
- F5 ↗
- Producti
- BIG-IP
- Added to KEVi
- March 27, 2026
- Remediation deadline (US Federal)i
- March 30, 2026(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.
Related vulnerabilities
F5 BIG-IP: Obejście uwierzytelnienia i zdalne wykonanie poleceń (RCE)
F5 BIG-IP: Pominięcie uwierzytelnienia iControl REST (RCE)
Buffer overflow w TMM URI normalization F5 BIG-IP — DoS/RCE
F5 BIG-IP/BIG-IQ iControl REST — nieuwierzytelniony RCE
F5 BIG-IP TMUI — krytyczny RCE przez path traversal (CVE-2020-5902)