On September 22, 2026, F5 published a security advisory and shipped emergency hotfixes for CVE-2026-94127, a critical, unauthenticated remote code execution vulnerability in BIG-IP Access Policy Manager (APM) — and confirmed it was already being exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog the same day and gave federal civilian agencies until September 25, 2026 to apply F5's mitigations. If you run BIG-IP APM as an OAuth authorization server, this is a today problem, not a backlog item.
What the bug actually is
CVE-2026-94127 is a heap-based buffer overflow (CWE-122) in BIG-IP APM. F5 rates it 9.8 out of 10 on CVSS v3.1 (9.3 on v4.0) — the practical difference between the two scoring versions doesn't matter here; both land in "drop everything." An unauthenticated attacker with network access to a vulnerable virtual server can send specially crafted traffic and get code execution on the appliance, no credentials or user interaction required.
The vulnerability is not exposed by default. It only affects BIG-IP virtual servers where an APM access policy and an OAuth authorization server profile are configured together on the same virtual server — meaning the appliance is acting as an OAuth Authorization Server, issuing access tokens to applications. BIG-IP instances using APM purely as an OAuth client or resource server are not affected. F5 says systems running in Appliance mode — normally a hardening layer — are also vulnerable. It describes this as a data-plane issue with no control-plane exposure, so locking down the management interface does not protect you here; the traffic that triggers it hits the virtual server itself.
F5 has published hotfixes across its supported branches:
- 21.1.0 →
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG - 17.5.0–17.5.1 →
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG - 17.1.0–17.1.3 →
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
For teams that can't patch immediately, F5 is distributing an iRule-based mitigation through F5 Support as a stopgap — you have to open a support case to get it, it isn't posted publicly.
How it's being exploited, and how to check
F5's advisory tells customers to look for a specific pattern in logs: a combination of multiple OAuth authentication failures and suspicious commands, followed shortly by a TMM (Traffic Management Microkernel) process crash with a SIGABRT. That crash signature is the practical indicator of compromise security teams are being told to hunt for — a normal OAuth failure doesn't take down TMM. No specific threat actor had been publicly named in connection with the exploitation in the coverage available at publication, and Rapid7 noted no confirmed public proof-of-concept at the time.
The internet-facing exposure is not small. Shadowserver tracks over 14,700 IP addresses with BIG-IP APM fingerprints, per BleepingComputer, though there's no information on how many of those are already patched or are honeypots rather than production gear. Given that this specific vulnerability only bites when APM is configured as an OAuth Authorization Server, the real at-risk population is a subset of that — but there's no public tally of how many of those 14,700 have that specific configuration turned on.
The context that makes this land harder
This isn't F5's first bad year. In October 2025, F5 disclosed that a nation-state actor had breached its systems (an intrusion it had detected in August 2025) and stolen part of its BIG-IP source code and vulnerability information, and CISA issued Emergency Directive ED 26-01 on October 15, 2025 — a mandate for federal agencies to inventory every BIG-IP device, check whether management interfaces were internet-facing, apply the latest updates on a hard deadline, and report back to CISA. That directive already put a standing obligation on federal agencies to apply any subsequent F5 security update within one week of release, specifically because of the risk that the stolen source code could surface as new exploited vulnerabilities down the line. CVE-2026-94127 is the kind of event that directive was written to anticipate: a previously undisclosed BIG-IP flaw, exploited before most customers had a chance to patch. The public reporting available does not establish a confirmed causal link between the 2025 source-code theft and this specific vulnerability, so treat that as background risk context, not an established fact — but it's the reason federal responses moved on a three-day clock instead of the usual patch cycle.
What this changes
For anyone running BIG-IP APM: check today whether any virtual server has both an APM access policy and an OAuth authorization server profile attached. If so, treat this as an incident-response task, not a maintenance-window task — apply the hotfix or the F5-provided iRule mitigation now, and search TMM logs for the OAuth-failure-then-SIGABRT pattern F5 describes. If you don't run APM as an OAuth authorization server, you're not exposed by this specific CVE, but it's still worth confirming that assumption rather than assuming it from memory of how the appliance was configured a year ago — configuration drift is exactly how "we don't use that feature" stops being true.
For engineering teams more broadly, the pattern here is familiar and worth internalizing regardless of vendor: OAuth/token-issuing components are increasingly a preferred target because a single RCE against an authorization server can cascade into every application that trusts its tokens. If your organization runs any on-prem OAuth authorization server — F5 APM, a self-hosted identity provider, or a homegrown token service — this is a reasonable prompt to check patch cadence and exposure on that specific component, not just the perimeter firewall. Wise Hustlers works on backend architecture and access-control hardening as part of its cybersecurity services, including reviewing exactly this kind of authentication-layer exposure.
Watch for whether F5 or CISA publish more detail tying this exploitation to a named threat actor, and whether the population of exposed OAuth-configured APM instances gets independently measured — both would change how urgent this looks in three months versus how urgent it looks today.
Sources
- CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM — Rapid7
- AL26-022 — Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127 — Canadian Centre for Cyber Security
- F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks — BleepingComputer
- F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers — The Hacker News
- Critical F5 BIG-IP Vulnerability Exploited as Zero-Day — SecurityWeek
- ED 26-01: Mitigate Vulnerabilities in F5 Devices — CISA