F5 BIG-IP Access Policy Manager (APM) contains a heap-based buffer overflow (CWE-122) that is reachable when a virtual server has both an APM access policy and an OAuth profile configured. An unauthenticated remote attacker can send specifically crafted malicious traffic to such a virtual server and achieve remote code execution on the BIG-IP system, which fully compromises the confidentiality, integrity, and availability of the traffic-management device. Systems running in Appliance mode are also vulnerable, and because this is a data plane flaw, the exposure is at the virtual server itself rather than the management control plane. The vulnerability is rated critical (CVSS 4.0: 9.3) with no privileges or user interaction required. No public proof-of-concept or confirmed in-the-wild exploitation is known, and F5 has not evaluated software versions that have reached End of Technical Support.
What to do: Inventory virtual servers with an APM access policy plus an OAuth profile and prioritize patching those first, applying the fixed release identified in F5's advisory (EoTS versions must be upgraded to a supported release to receive a fix). Until patched, remove the OAuth profile from internet-facing virtual servers where feasible or restrict access to the virtual server so untrusted sources cannot reach the APM listener. Monitor BIG-IP logs for anomalous traffic to APM-enabled virtual servers, since exploitation would not touch the management plane.
Affected
F5 BIG-IP (Access Policy Manager)
—
Estimated exposure
moderatelikely on the order of a few thousand internet-exposed virtual servers (subset of the tens of thousands of BIG-IP devices visible in public scans) — Public internet scans (Shodan/Censys) typically show tens of thousands of exposed BIG-IP systems, but only the subset licensed for APM with both an access policy and an OAuth profile on a virtual server is vulnerable, which sharply narrows…
Description
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CISA Known Exploited Vulnerability
Affected
F5 BIG-IP APM
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
F5 has patched a critical zero-day vulnerability (CVE-2026-94127) in its BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution. The flaw, a heap-based buffer overflow rated 9.8 on CVSS v3.1, is actively being exploited in the wild. It affects only BIG-IP systems configured to use APM as an OAuth authorization server. CISA has added the CVE to its Known Exploited Vulnerabilities catalog and mandated federal agencies apply mitigations by September 25.
F5 and CISA warned of an actively exploited critical zero-day (CVE-2026-94127) in BIG-IP APM enabling unauthenticated remote code execution.
F5 and CISA have warned that a critical zero-day vulnerability in F5 BIG-IP Access Policy Manager (APM) is being actively exploited. Tracked as CVE-2026-94127 with a CVSS score of 9.8, the flaw allows unauthenticated attackers to achieve remote code execution via malicious traffic when APM is configured as an OAuth Authorization Server. F5 has released hotfixes for affected versions, and CISA has added the CVE to its KEV list, mandating federal agencies patch within three days.
F5 patched actively exploited BIG-IP APM zero-day CVE-2026-94127, a 9.8 CVSS heap overflow RCE added to CISA's KEV catalog.
F5 fixed critical remote code execution flaw CVE-2026-94127 (CVSS 9.8), a heap-based buffer overflow affecting BIG-IP APM deployments configured as OAuth authorization servers, which was actively exploited before the patch released. CISA added the zero-day to its Known Exploited Vulnerabilities catalog, and Shadowserver tracks more than 15,000 internet-exposed BIG-IP APM deployments. Hotfixes cover the 21.x, 17.5.x, and 17.1.x branches, with an iRule available as interim mitigation. F5 advises reviewing logs for repeated OAuth authentication failures, suspicious commands, and TMM SIGABRT crashes as exploitation indicators.
CISA adds four actively exploited zero-days to KEV, forcing immediate patching of critical flaws in Check Point, Arista, and F5 systems.
CISA has added four actively exploited zero-day vulnerabilities to its KEV catalog, forcing US federal agencies to patch by September 25. The list includes critical flaws in Check Point Security Management (CVE-2026-93616) and Security Gateway (CVE-2026-85102), alongside zero-days in Arista VeloCloud Orchestrator (CVE-2026-93952) and F5 BIG-IP APM (CVE-2026-94127). Check Point confirmed exploitation against Management Servers and Spark firewalls globally.
F5 patches critical CVSS 9.8 heap-based buffer overflow (CVE-2026-94127) in BIG-IP APM that allows unauthenticated RCE, now added to CISA KEV list.
F5 has patched a critical heap-based buffer overflow vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager (APM) that could allow unauthenticated remote code execution. The flaw, with a CVSS v3.1 score of 9.8, is exploitable by sending specially crafted traffic to a vulnerable virtual server configured with both an APM access policy and an OAuth profile. The vulnerability affects the data plane and has been added to the CISA KEV list. F5 has provided hotfixes for affected release trains.
watchTowr details actively exploited unauthenticated heap overflow CVE-2026-94127 in F5 BIG-IP APM, enabling RCE via oversized Authorization headers.
F5 advisory K000162605 (published Sept 22) discloses CVE-2026-94127, an unauthenticated heap overflow in BIG-IP APM where an oversized Authorization header overflows a 0x4100-byte heap buffer, allowing pre-auth RCE on appliances at the network edge. F5 states the vulnerability is being actively exploited. watchTowr patch-diffed BIG-IP 21.1.0 against the fixed hotfix build using IDA and Diaphora across 1,728 functions, finding the fix adds a size check rejecting Authorization headers over 0x4100 bytes. Fixes are hotfix ISOs for the 21.1.0, 17.5.1, and 17.1.3 branches; other BIG-IP modules and BIG-IQ are listed as not affected.
Attackers are exploiting critical F5 BIG-IP APM zero-day CVE-2026-94127 for unauthenticated remote code execution.
F5 disclosed CVE-2026-94127, a critical flaw scored CVSS 9.8 in BIG-IP Access Policy Manager, which lets an unauthenticated attacker execute arbitrary code when APM is an OAuth Authorization Server with an access policy and OAuth profile on the same virtual server. Affected releases are BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0; hotfixes are out and an iRule is only a temporary mitigation. F5 confirmed in-the-wild exploitation, and CISA added the bug to the KEV catalog with a September 25, 2026 federal deadline. The issue is data-plane only, appliance mode is vulnerable, and Shadowserver sees more than 14,700 BIG-IP APM fingerprints, not a confirmed vulnerable count.
F5 says CVE-2026-94127, a critical unauthenticated BIG-IP APM RCE, is already exploited in the wild.
F5 disclosed CVE-2026-94127, a heap-based buffer overflow in BIG-IP Access Policy Manager scored CVSS 9.8 (v3.1) and 9.3 (v4.0), and said it is already exploited. Unauthenticated attackers can execute code when an APM virtual server is configured as an OAuth Authorization Server. Affected releases include 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3, with engineering hotfixes available. Indicators include repeated OAuth failures, suspicious command activity, and TMM crashes producing SIGABRT.
Attackers are exploiting critical F5 BIG-IP APM zero-day CVE-2026-94127; CISA added it to KEV.
The Register reports F5 patched CVE-2026-94127, a heap-based buffer overflow in BIG-IP Access Policy Manager scored 9.3 on CVSS v4.0, affecting systems configured as an OAuth Authorization Server with an access policy and OAuth profile on the same virtual server. F5 and CISA say unknown attackers are exploiting it for remote code execution, and CISA gave federal agencies until Friday to patch. The article recalls a prior highly sophisticated intrusion in which attackers stole BIG-IP source code, undisclosed vulnerability details, and some customer configuration data. It also notes Mandiant previously linked exploitation of CVE-2023-46747 to UNC5174, assessed with moderate confidence as China-based.
F5 patched actively exploited BIG-IP APM zero-day CVE-2026-94127 enabling remote code execution; CISA added it to KEV with a federal patch deadline.
F5 released updates for critical BIG-IP APM zero-day CVE-2026-94127, which is exploited in remote code execution attacks against instances configured as an OAuth Authorization Server. CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by Friday. Shadowserver tracks over 14,700 internet-exposed BIG-IP APM IPs, and admins unable to patch immediately can apply an F5-provided iRule mitigation. F5 advises checking for multiple OAuth authentication failures followed by suspicious commands and a TMM SIGABRT as indicators of compromise.
Attackers are exploiting F5 BIG-IP APM OAuth zero-day CVE-2026-94127 for unauthenticated remote code execution.
F5 says attackers are exploiting CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager, for unauthenticated remote code execution. The flaw affects virtual servers configured with both an APM access policy and an OAuth Authorization Server profile, scoring CVSS v3.1 9.8 and CVSS v4.0 9.3. Known vulnerable releases include 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3; engineering hotfixes and an optional iRule mitigation are available. CISA added the CVE to its Known Exploited Vulnerabilities catalog, while attacker identity and exploitation scale are not established.
F5 shipped emergency fixes for CVE-2026-94127, a critical BIG-IP APM flaw under active exploitation.
F5 released emergency engineering hotfixes for CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager. The report describes the issue as a remote code execution flaw and says it is under active exploitation. The available text does not list affected versions, indicators, or the attackers involved.
On 22 September 2026, CERT-EU warned that F5 BIG-IP APM vulnerability CVE-2026-94127, a CVSS 9.8 heap-based buffer overflow, allows unauthenticated remote code execution when an access policy and OAuth profile are configured on a virtual server. F5 confirmed active exploitation. Affected versions include 17.1.0–17.1.3, 17.5.0–17.5.1, and 21.1.0. CERT-EU urges immediate hotfixes, evidence preservation, and checks for OAuth failures followed by suspicious commands and TMM crashes.
CISA added four actively exploited Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its KEV catalog, with federal fixes due September 25.
CISA added CVE-2026-85102 (Check Point VPN certificate validation bypass), CVE-2026-93616 (Check Point Security Management Server path traversal), CVE-2026-93952 (Arista VeloCloud Orchestrator input validation), and CVE-2026-94127 (F5 BIG-IP APM heap buffer overflow) to the KEV catalog. Check Point stated CVE-2026-93616 is exploited in the wild with a handful of customers already attacked, and F5 confirmed exploitation of CVE-2026-94127 against APM OAuth Authorization Server configurations. Federal agencies must remediate by September 25, 2026 under BOD 22-01. Check Point has shipped LivePatch/Jumbo Hotfixes and an R82.20 Security Hotfix, plus IOCs for detection.
Canada's Cyber Centre warns F5 BIG-IP APM flaw CVE-2026-94127 is being exploited in the wild.
The Canadian Centre for Cyber Security issued advisory AV26-949 on September 22, 2026, for an F5 BIG-IP APM vulnerability. CVE-2026-94127 affects BIG-IP 21.1.0 through hotfix 21.1.0.2.0.30.22, 17.5.0 through hotfix 17.5.1.9.0.160.12, and 17.1.0 through hotfix 17.1.3.5.0.41.14. F5 reported the flaw is being exploited in the wild. Administrators are urged to review F5 article K000162605 and apply updates.
Canadian Cyber Centre warns CVE-2026-94127, a critical heap buffer overflow in F5 BIG-IP APM enabling unauthenticated RCE, is exploited in the wild.
CVE-2026-94127 is a heap-based buffer overflow (CWE-122) affecting F5 BIG-IP systems where an APM access policy and an OAuth profile are configured on the same virtual server, allowing unauthenticated attackers remote code execution and full system compromise. F5 has indicated the vulnerability is being exploited in the wild. Fixed hotfixes are available for BIG-IP APM versions 17.1.0, 17.5.0, and 21.1.0, and the Cyber Centre recommends applying an F5-provided iRule and reviewing logs for indicators including rapid or high-volume OAuth authentication failures.
CISA added four actively exploited Check Point, Arista VeloCloud, and F5 BIG-IP flaws to the KEV catalog.
On 2026-09-22, CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. They are CVE-2026-85102 (Check Point improper certificate validation), CVE-2026-93616 (Check Point path traversal), CVE-2026-93952 (Arista VeloCloud Orchestrator improper input validation), and CVE-2026-94127 (F5 BIG-IP APM heap-based buffer overflow). Binding Operational Directive 26-04 requires federal civilian agencies to prioritize remediation of high-risk KEV entries on exposed assets. CISA encourages all organizations to remediate these cataloged flaws quickly.