Critical F5 BIG-IP APM Flaw Enables Remote Code Execution; Patch Urgency Intensifies Amid Active Exploits
September 23, 2026
A critical vulnerability in F5 BIG-IP Access Policy Manager (APM) allows unauthenticated remote code execution when APM serves as an OAuth authorization server, tracked as CVE-2026-94127.
The flaw is a heap-based buffer overflow with very high severity, scoring 9.8/10 on CVSS v3.1 and 9.3/10 on CVSS v4.0.
This is a data plane issue that also affects appliance mode; there is no exposure on the control plane.
F5 has released hotfixes for affected versions (17.1.x, 17.5.x, 21.1.x) and provides an iRule mitigation for environments where immediate hotfix installation isn’t possible.
Mitigations stress applying patches promptly, deploying the iRule, restricting affected virtual servers, and increasing logging and monitoring across devices and networks.
Vendor guidance lists specific hotfix identifiers per release branch and cautions that simply seeing an “OAuth” label does not reveal exposure level.
Public exploitation has been observed in the wild, with KEV catalog inclusion and a focus on data plane impact rather than control plane.
CERT-EU and other alerts say exploitation could lead to full system compromise, urging rapid patching and assessment of identity services and connected apps.
F5 provides IOC guidance: repeated OAuth failures, suspicious commands, and TMM core events help detect compromise, with correlated logs across endpoints.
CISA added CVE-2026-94127 to the Known Exploited Vulnerabilities catalog and set patching deadlines for federal agencies, underscoring urgency.
SOCs and organizations should conduct emergency investigations, verify product versions and OAuth server configurations, and coordinate between security operations and admins.
Temporary mitigation via F5 iRule is available, but it does not replace the need for the official hotfix.
Summary based on 6 sources
Get a daily email with more Tech stories
Sources

SecurityWeek • Sep 23, 2026
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
The Hacker News • Sep 23, 2026
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Security Affairs • Sep 23, 2026
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
theregister • Sep 23, 2026
Someone's attacking a critical 0-day RCE in F5 BIG-IP APM