F5 BIG-IP APM OAuth zero-day CVE-2026-94127 exploited for unauthenticated RCE; hotfixes shipped and CISA sets September 25 federal patch deadline
F5 patched CVE-2026-94127, a CVSS 9.8 heap-based buffer overflow in BIG-IP APM that gives unauthenticated attackers remote code execution on virtual servers configured as OAuth Authorization Servers; the flaw is actively exploited, sits on CISA's KEV list…
F5 advisory K000162605 (published September 22, 2026) discloses CVE-2026-94127, a heap-based buffer overflow on the BIG-IP data plane that lets an unauthenticated attacker with network access achieve remote code execution by sending crafted traffic — per watchTowr, an oversized Authorization header overflowing a 0x4100-byte heap buffer — to a virtual server configured with both an APM access policy and an OAuth Authorization Server profile. The flaw is rated CVSS v3.1 9.8 and CVSS v4.0 9.3 (The Register cites only the 9.3 v4.0 figure), and F5 confirms active exploitation in the wild, though attacker identity, scale, and post-compromise objectives remain unconfirmed. Affected releases are 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3; engineering hotfix ISOs cover those branches (watchTowr lists fixed builds for 21.1.0, 17.5.1, and 17.1.3), and the fix adds a size check rejecting Authorization headers over 0x4100 bytes, which watchTowr verified by patch-diffing 21.1.0 against the fixed build across 1,728 functions using IDA and Diaphora. An F5-provided iRule is available only as a temporary, support-only interim mitigation. BIG-IP Next, BIG-IQ, NGINX, F5OS, and other BIG-IP modules are not vulnerable, though Security Affairs notes appliance mode remains vulnerable. CISA added the CVE to its Known Exploited Vulnerabilities catalog on Tuesday, requiring federal agencies to patch by September 25, 2026 (also described as Friday or within three days). Exposure figures disagree: BleepingComputer and Security Affairs report Shadowserver tracking more than 14,700 internet-exposed BIG-IP APM IP fingerprints (explicitly not a confirmed vulnerable count), while CSO Online reports more than 15,000 exposed deployments. Indicators of compromise are repeated OAuth authentication failures followed by suspicious command activity and TMM crashes producing SIGABRT. Historical context only: The Register notes a prior sophisticated F5 intrusion that stole BIG-IP source code, undisclosed vulnerability details, and some customer configuration data, and Mandiant's moderate-confidence link of older CVE-2023-46747 exploitation to China-nexus UNC5174.
- CVE-2026-94127 is a heap-based buffer overflow in BIG-IP Access Policy Manager allowing unauthenticated remote code execution; rated CVSS v3.1 9.8 and CVSS v4.0 9.3 (The Register cites only 9.3).
- Exploitation requires a virtual server configured with both an APM access policy and an OAuth Authorization Server profile; the issue is data-plane only, and appliance mode is still vulnerable.
Coverage timelineoldest first · each row is one article
- · 5d ago2026-013: Critical Vulnerability in F5 BIG-IP APM
CERT-EU Advisories· 86
CERT-EU says exploited F5 BIG-IP APM flaw CVE-2026-94127 allows unauthenticated remote code execution.
- · 4d agoF5 security advisory (AV26-949)
Canadian Centre for Cyber Security· 82
Canada's Cyber Centre warns F5 BIG-IP APM flaw CVE-2026-94127 is being exploited in the wild.
- · 4d agoAL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127
Canadian Centre for Cyber Security· 80
Canadian Cyber Centre warns CVE-2026-94127, a critical heap buffer overflow in F5 BIG-IP APM enabling unauthenticated RCE, is exploited in the wild.
Vulnerabilities in this storyAll →
- CVE-2023-467479.897%F5 BIG-IP TMUI Authentication Bypass Enables Unauthenticated RCEpublished · f5 BIG-IP Access Policy Manager KEV ransomware PoC ×2