Skip to main content
The Wire
CyberNews by Zentrya One
critical CVE-2026-94127 Vulnerabilities

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE

F5 patches CVE-2026-94127, a critical CVSS 9.8 BIG-IP APM zero-day actively exploited to achieve unauthenticated remote code execution on OAuth authorization servers.

F5 has released emergency fixes for a critical BIG-IP Access Policy Manager (APM) zero-day vulnerability that attackers are already exploiting to achieve unauthenticated remote code execution.

Tracked as CVE-2026-94127, the heap-based buffer overflow carries a CVSS v3.1 score of 9.8 and CVSS v4.0 score of 9.3. F5 disclosed the vulnerability on September 22, 2026, after learning that it had been exploited in real-world attacks.

CVE-2026-94127 at a Glance

Detail Information
CVE CVE-2026-94127
Product F5 BIG-IP Access Policy Manager
Vulnerability Heap-based buffer overflow
CVSS v3.1 9.8 – Critical
CVSS v4.0 9.3
Authentication Not required
Impact Remote Code Execution
Exploitation Confirmed active
Fix F5 engineering hotfixes

Which BIG-IP Systems Are Vulnerable?

The vulnerability does not affect every BIG-IP APM deployment.

Exploitation requires a virtual server configured with both:

  • A BIG-IP APM access policy, and
  • An OAuth profile where APM operates as an OAuth authorization server.

In this configuration, specially crafted network traffic sent to the virtual server can trigger the vulnerability and potentially result in arbitrary code execution.

The attack path can be summarized as:

Unauthenticated Attacker → Crafted OAuth Traffic → Vulnerable APM Virtual Server → Heap Buffer Overflow → Remote Code Execution

F5 says systems running in Appliance mode remain vulnerable.

Management Interface Restrictions Won't Stop the Attack

An important detail is that exploitation targets the virtual server receiving OAuth traffic, rather than the BIG-IP management interface.

As a result, restricting access to the management interface alone does not mitigate CVE-2026-94127.

This makes internet-accessible OAuth authorization servers particularly important to identify and patch.

Active Exploitation Confirmed

F5 has confirmed that CVE-2026-94127 has been exploited, although the company has not publicly disclosed the threat actors responsible, targeted organizations, number of compromised systems, or post-exploitation activity.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on September 22.

Federal civilian agencies were given until September 25, 2026 to apply the required mitigations.

F5 Releases Emergency Hotfixes

F5 has released engineering hotfixes for affected BIG-IP branches.

Organizations running vulnerable configurations should contact F5 Support and deploy the appropriate hotfix as soon as possible.

Where immediate patching is not possible, F5 provides an iRule-based mitigation for affected virtual servers through its support channel.

Security teams should also investigate potentially exposed systems for:

  • Unexpected processes or command execution
  • Unusual OAuth requests
  • Configuration changes
  • New accounts or persistence mechanisms
  • Unexpected outbound network connections
  • Suspicious files or scripts
  • Abnormal activity originating from BIG-IP appliances

Because exploitation occurred before public disclosure, patching should be combined with a compromise assessment for systems that were previously exposed.

Security Takeaway

CVE-2026-94127 is particularly dangerous because it combines three important characteristics:

No Authentication → Network Accessible → Remote Code Execution

However, exposure is limited to BIG-IP APM systems configured as OAuth authorization servers with the required access policy and OAuth profile on the same virtual server.

With active exploitation already confirmed, affected organizations should prioritize deployment of F5's engineering hotfixes and investigate exposed BIG-IP systems for evidence of compromise.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.