Security advisories

Critical BIG-IP APM Zero-Day Vulnerability Under Exploitation (CVE-2026-94127)

September 23, 2026

3 MINS READ

THE THREAT

On September 22nd, 2026, F5 disclosed CVE-2026-94127 (CVSS: 9.8), a zero-day heap-based buffer overflow vulnerability within BIG-IP Access Policy Manager (APM). When a BIG-IP APM access policy and OAuth profile are configured on a virtual server, attackers can send malicious traffic to the impacted device which can lead to unauthenticated Remote Code Execution (RCE).

CVE-2026-94127 impacts BIG-IP APM versions 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0; patches have been released to address the vulnerability. F5 states that exploitation of CVE-2026-94127 has been observed in the wild. Impacted organizations should ensure that relevant patches are applied as soon as possible.

What we're doing about it

What you should do about it

Additional information

F5 states that CVE-2026-94127 only impacts BIG-IP APM when it is configured as an OAuth Authorization server; organizations that deploy BIG-IP APM strictly as an OAuth Client or Resource Server, without OAuth Authorization server profiles configured, are not affected by the flaw. As the vulnerability impacts the data plane, responsible for network traffic processing, a temporary mitigation that can be applied to reduce exposure until patching is the use of an iRule supplied by F5 Support; F5 notes that the Support team must be contacted to retrieve the rule.

F5 indicates within the advisory that attacks leveraging CVE-2026-94127 have been observed in the wild, but no additional details regarding these attacks have been shared. At the time of writing, technical details regarding the flaw are limited, and there is no publicly available Proof-of-Concept (PoC) exploit code. Following F5's disclosure, CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies a deadline of September 25th to apply relevant patches. As exploitation has been observed for CVE-2026-94127, impacted organizations should ensure that relevant patches are applied as soon as possible.

Impacted Product List
Product Vulnerable Version First Fixed Version
BIG-IP APM 17.1.0 - 17.1.3 Hotfix-BIGIP 17.1.3.5.0.41.14-ENG.iso
17.5.0 - 17.5.1 Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso
21.1.0 Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso

References:
[1] https://my.f5.com/manage/s/article/K000162605
[2] https://nvd.nist.gov/vuln/detail/cve-2026-94127
[3] https://my.f5.com/manage/s/article/K000135931
[4] https://my.f5.com/manage/s/article/K44525501
[5] https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories