F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE
F5 patches CVE-2026-94127, a critical CVSS 9.8 BIG-IP APM zero-day actively exploited to achieve unauthenticated remote code execution on OAuth authorization servers.

F5 has released emergency fixes for a critical BIG-IP Access Policy Manager (APM) zero-day vulnerability that attackers are already exploiting to achieve unauthenticated remote code execution.
Tracked as CVE-2026-94127, the heap-based buffer overflow carries a CVSS v3.1 score of 9.8 and CVSS v4.0 score of 9.3. F5 disclosed the vulnerability on September 22, 2026, after learning that it had been exploited in real-world attacks.
CVE-2026-94127 at a Glance
| Detail | Information |
|---|---|
| CVE | CVE-2026-94127 |
| Product | F5 BIG-IP Access Policy Manager |
| Vulnerability | Heap-based buffer overflow |
| CVSS v3.1 | 9.8 – Critical |
| CVSS v4.0 | 9.3 |
| Authentication | Not required |
| Impact | Remote Code Execution |
| Exploitation | Confirmed active |
| Fix | F5 engineering hotfixes |
Which BIG-IP Systems Are Vulnerable?
The vulnerability does not affect every BIG-IP APM deployment.
Exploitation requires a virtual server configured with both:
- A BIG-IP APM access policy, and
- An OAuth profile where APM operates as an OAuth authorization server.
In this configuration, specially crafted network traffic sent to the virtual server can trigger the vulnerability and potentially result in arbitrary code execution.
The attack path can be summarized as:
Unauthenticated Attacker → Crafted OAuth Traffic → Vulnerable APM Virtual Server → Heap Buffer Overflow → Remote Code Execution
F5 says systems running in Appliance mode remain vulnerable.
Management Interface Restrictions Won't Stop the Attack
An important detail is that exploitation targets the virtual server receiving OAuth traffic, rather than the BIG-IP management interface.
As a result, restricting access to the management interface alone does not mitigate CVE-2026-94127.
This makes internet-accessible OAuth authorization servers particularly important to identify and patch.
Active Exploitation Confirmed
F5 has confirmed that CVE-2026-94127 has been exploited, although the company has not publicly disclosed the threat actors responsible, targeted organizations, number of compromised systems, or post-exploitation activity.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on September 22.
Federal civilian agencies were given until September 25, 2026 to apply the required mitigations.
F5 Releases Emergency Hotfixes
F5 has released engineering hotfixes for affected BIG-IP branches.
Organizations running vulnerable configurations should contact F5 Support and deploy the appropriate hotfix as soon as possible.
Where immediate patching is not possible, F5 provides an iRule-based mitigation for affected virtual servers through its support channel.
Security teams should also investigate potentially exposed systems for:
- Unexpected processes or command execution
- Unusual OAuth requests
- Configuration changes
- New accounts or persistence mechanisms
- Unexpected outbound network connections
- Suspicious files or scripts
- Abnormal activity originating from BIG-IP appliances
Because exploitation occurred before public disclosure, patching should be combined with a compromise assessment for systems that were previously exposed.
Security Takeaway
CVE-2026-94127 is particularly dangerous because it combines three important characteristics:
No Authentication → Network Accessible → Remote Code Execution
However, exposure is limited to BIG-IP APM systems configured as OAuth authorization servers with the required access policy and OAuth profile on the same virtual server.
With active exploitation already confirmed, affected organizations should prioritize deployment of F5's engineering hotfixes and investigate exposed BIG-IP systems for evidence of compromise.
Related reporting
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
Warlock ransomware attackers exploit Microsoft SharePoint vulnerabilities to gain initial access, disable security tools and distribute ransomware across critical infrastructure networks.
Apple CoreGraphics Zero-Day PoC Emerges as WhatsApp PDF Checks Raise Delivery Questions
A public PoC for Apple CoreGraphics CVE-2026-86950 demonstrates memory corruption through a malicious PDF, while new WhatsApp PDF protections raise questions about a possible delivery path.
Kiteworks Fixes Critical Vulnerability Discovered During Emergency Shutdown
Kiteworks patched a previously unknown critical vulnerability discovered during a nine-hour precautionary shutdown prompted by intelligence about a potential cyberattack, with no evidence of exploitation.


