F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
Attackers are exploiting critical F5 BIG-IP APM zero-day CVE-2026-94127 for unauthenticated remote code execution.
F5 disclosed CVE-2026-94127, a critical flaw scored CVSS 9.8 in BIG-IP Access Policy Manager, which lets an unauthenticated attacker execute arbitrary code when APM is an OAuth Authorization Server with an access policy and OAuth profile on the same virtual server. Affected releases are BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0; hotfixes are out and an iRule is only a temporary mitigation. F5 confirmed in-the-wild exploitation, and CISA added the bug to the KEV catalog with a September 25, 2026 federal deadline. The issue is data-plane only, appliance mode is vulnerable, and Shadowserver sees more than 14,700 BIG-IP APM fingerprints, not a confirmed vulnerable count.
- CVE-2026-94127 scores 9.8 and allows unauthenticated remote code execution.
- Affects APM only when configured as an OAuth Authorization Server.
- Vulnerable branches: 17.1.0-17.1.3, 17.5.0-17.5.1, and 21.1.0.
- CISA added it to KEV; federal deadline is September 25, 2026.
- Shadowserver tracks over 14,700 BIG-IP APM IP fingerprints.
Vulnerabilities mentionedAll →
- CVE-2026-941279.32%Unauthenticated Heap-Overflow RCE in F5 BIG-IP APM with OAuth Profilepublished · F5 BIG-IP (Access Policy Manager) KEV PoC ×2
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article568 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 23, 2026

F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it.
F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild.
The flaw can allow an unauthenticated attacker to execute arbitrary code on a vulnerable BIG-IP system. F5 disclosed the issue on September 22 and confirmed that exploitation had already been observed.
The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server. More specifically, the vulnerable configuration is one in which APM operates as an OAuth Authorization Server. Systems using APM only as an OAuth Client or Resource Server are not affected.
“When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. (CVE-2026-94127)” reads the advisory. “This vulnerability allows an unauthenticated attacker to perform RCE. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. We have learned that this vulnerability has been exploited.”
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0. The company has released hotfixes for the vulnerable branches. The flaw affects the data plane rather than the BIG-IP management plane, and F5 says the appliance mode is also vulnerable.
The attack is particularly concerning because BIG-IP appliances are commonly positioned at the edge of corporate networks and handle authentication and access to internal applications. A successful compromise could therefore give an attacker a valuable position from which to move deeper into an organization’s infrastructure.
F5 has also provided indicators that defenders can use to look for signs of exploitation. The company recommends paying particular attention to environments showing repeated OAuth authentication failures followed by suspicious commands and, shortly afterward, a TMM SIGABRT event.
Organizations that cannot immediately install the hotfix can apply a temporary mitigation. F5 recommends deploying an iRule provided through its support channels to the affected BIG-IP APM virtual server. However, this should be considered a temporary measure rather than a replacement for the security update.
Shortly after F5 published its advisory, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog. US federal agencies were instructed to address the vulnerability by September 25, 2026.
Internet exposure also appears significant. Shadowserver is currently tracking more than 14,700 IP addresses showing BIG-IP APM fingerprints, although this number does not indicate how many systems are actually vulnerable or unpatched.
For organizations running BIG-IP APM, the immediate priority is to determine whether the affected OAuth configuration is in use, identify exposed systems, install the appropriate hotfix and review logs for possible compromise.
Because F5 has confirmed active exploitation, administrators should also treat patching as an incident-response priority rather than as routine vulnerability management.
F5 advisory and technical details: F5 BIG-IP APM security advisory
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, F5 BIG-IP)