Critical F5 BIG-IP APM Flaw Enables Remote Code Execution; Patch Urgency Intensifies Amid Active Exploits

September 23, 2026
Critical F5 BIG-IP APM Flaw Enables Remote Code Execution; Patch Urgency Intensifies Amid Active Exploits
  • A critical vulnerability in F5 BIG-IP Access Policy Manager (APM) allows unauthenticated remote code execution when APM serves as an OAuth authorization server, tracked as CVE-2026-94127.

  • The flaw is a heap-based buffer overflow with very high severity, scoring 9.8/10 on CVSS v3.1 and 9.3/10 on CVSS v4.0.

  • This is a data plane issue that also affects appliance mode; there is no exposure on the control plane.

  • F5 has released hotfixes for affected versions (17.1.x, 17.5.x, 21.1.x) and provides an iRule mitigation for environments where immediate hotfix installation isn’t possible.

  • Mitigations stress applying patches promptly, deploying the iRule, restricting affected virtual servers, and increasing logging and monitoring across devices and networks.

  • Vendor guidance lists specific hotfix identifiers per release branch and cautions that simply seeing an “OAuth” label does not reveal exposure level.

  • Public exploitation has been observed in the wild, with KEV catalog inclusion and a focus on data plane impact rather than control plane.

  • CERT-EU and other alerts say exploitation could lead to full system compromise, urging rapid patching and assessment of identity services and connected apps.

  • F5 provides IOC guidance: repeated OAuth failures, suspicious commands, and TMM core events help detect compromise, with correlated logs across endpoints.

  • CISA added CVE-2026-94127 to the Known Exploited Vulnerabilities catalog and set patching deadlines for federal agencies, underscoring urgency.

  • SOCs and organizations should conduct emergency investigations, verify product versions and OAuth server configurations, and coordinate between security operations and admins.

  • Temporary mitigation via F5 iRule is available, but it does not replace the need for the official hotfix.

Summary based on 6 sources


Get a daily email with more Tech stories

Sources

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day


F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks


More Stories