TL;DR
On September 22, 2026, F5 disclosed a critical flaw in its Access Policy Manager software. This severe BIG-IP APM vulnerability allows unauthenticated attackers to execute arbitrary code remotely. The vendor confirmed active attacks against unpatched systems in the wild.
- CVE: CVE-2026-94127
- CVSS: 9.8 (Critical · CVSSv3)
- Product: F5 BIG-IP
- Affected: 21.1.0, 17.5.0, 17.1.0
- Impact: BIG-IP APM OAuth vulnerability
- Status: Exploited in the wild
- Patched in: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
- Action: Update to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, Hotfix-BIGIP-17.1.3.5.0.41.14-ENG now
Track every F5 CVE the moment it's exploited.
Get free email alertsWhy It Matters
This flaw threatens mission-critical infrastructure across corporate environments. Sourced industry estimates show that tens of thousands of organizations deploy BIG-IP gateways globally. The security defect carries a critical CVSS v3.1 score of 9.8. F5 issued an urgent warning in its bulletin, stating, “We have learned that this vulnerability has been exploited.” Attackers can compromise systems without providing any valid credentials. Furthermore, appliances operating in Appliance mode also remain vulnerable. However, researchers have not confirmed any public proof-of-concept code yet. A successful breach gives attackers full access to sensitive enterprise traffic. Therefore, administrators must treat this threat as an urgent priority.
How The Attack Works
The flaw stems from a heap-based buffer overflow within the data plane. According to the official F5 security advisory, the weakness resides inside the Traffic Management Microkernel. Specifically, F5 noted, “When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE).” The vendor also emphasized, “This is a data plane issue; there is no control plane exposure.” An attacker transmits specially crafted network requests directly to an exposed virtual server. The system fails to validate memory boundaries during OAuth profile handling. Consequently, this memory corruption allows arbitrary code execution with elevated daemon privileges.
Affected Versions
The security vulnerability impacts multiple active branches of BIG-IP APM. Specifically, vulnerable releases include versions 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3. Other BIG-IP software modules and NGINX products remain unaffected.
Patch Or Mitigation Steps
Administrators should deploy the official engineering hotfixes immediately. F5 released hotfix packages for the 21.x and 17.x release trains. If immediate patching is not possible, apply an emergency iRule mitigation. Organizations can contact F5 Support directly to obtain the protective iRule script. Teams should also monitor logs for repeated OAuth authentication failures. Defending against this BIG-IP APM vulnerability prevents unauthorized network compromise.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!