F5 BIG-IP APM CVE-2026-94127 (CVSS 9.8) Unauthenticated RCE Zero-Day Actively Exploited on OAuth Authorization Servers

One CVSS 9.8, one OAuth-server config, one unauth RCE. F5 zero-day lands under active exploitation this week.

Share
Duotone photo of a rack-mounted access-policy appliance with coiled access cables, a single front-panel status light lit in signal red.

F5 has disclosed CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager (APM) that carries a CVSS score of 9.8 and lets an unauthenticated network attacker reach remote code execution. The company published its advisory on September 22, 2026, shipped engineering hotfixes the same day, and, along with the U.S. Cybersecurity and Infrastructure Security Agency (CISA), warns that the flaw is already under active exploitation. One qualifier decides who is exposed: the bug is only reachable when APM is configured as an OAuth authorization server issuing access tokens, a non-default setup that often sits at an organization's network edge.

If you run BIG-IP APM, the defender task this week is narrow and concrete. Confirm whether any virtual server pairs an APM access policy with an OAuth profile, apply the matching F5 hotfix to the affected release train, and hunt for signs of compromise on those data-plane devices. Everything below is the detail behind that three-step order, drawn from F5's advisory and from analysis by Rapid7, with reporting from The Hacker News and The Register.

What F5 Disclosed

F5 describes CVE-2026-94127 as a heap-based buffer overflow in BIG-IP APM that an unauthenticated attacker with network access to an affected virtual server can drive to remote code execution by sending specially crafted traffic. The CVSS v3.1 base score is 9.8, near the top of the scale, and it reflects the combination defenders dread most: no authentication required, reachable over the network, and code execution as the outcome. F5 released the advisory, tracked internally as K000162605, on September 22, 2026 and made engineering hotfixes available the same day rather than waiting for a scheduled maintenance release.

Two scoping details narrow where the risk lives. The flaw sits in the data plane, the part of BIG-IP that processes application traffic, and F5 says it does not expose the control plane. That means exposure is tied to how a virtual server handles traffic, not to management-interface access, so a locked-down admin network does not neutralize it. F5 also notes that systems running in Appliance mode, a hardened configuration that restricts administrative access, are affected as well. Appliance mode is not a mitigation for this CVE, and treating a hardened device as already safe would be a mistake.

Per Rapid7's analysis, F5 lists three affected release trains, each with a specific fixed build. BIG-IP 21.1.0 is vulnerable in versions prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG. BIG-IP 17.5.0 is vulnerable in versions prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG. And BIG-IP 17.1.0 is vulnerable in versions prior to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG. These are engineering hotfixes, F5's usual vehicle when it wants a targeted fix in operators' hands quickly. For teams that cannot patch immediately, F5 provides an iRule workaround through F5 Support, which means opening a support case and following F5's implementation guidance rather than copying a rule from a public writeup.

The OAuth-Authorization-Server Configuration Qualifier

The single most important line for triage is the precondition, because it splits the BIG-IP APM estate cleanly into exposed and not-exposed. Rapid7 states the flaw is "not exposed in a default configuration." Exploitation requires that APM be configured as an OAuth authorization server issuing access tokens, which in practice means a BIG-IP virtual server carrying both an APM access policy and an OAuth profile. BIG-IP APM delivers identity-aware access control for applications and corporate resources and can integrate with OAuth, OpenID Connect, and SAML, so the OAuth authorization-server role is one common deployment among several, not the only way APM is used.

Read that qualifier carefully, because it cuts both ways. It narrows the immediately exploitable population to one specific configuration, which is real relief for operators who run APM purely for SAML-based or standard access without the OAuth authorization-server role. But where that configuration exists, it usually exists at the edge, fronting the very applications an organization most wants to guard with identity-aware access. The precondition does not make this a minor issue. It makes it a targeted one. And this is the part worth labeling as assessment rather than reported fact: an internet-facing OAuth authorization server is precisely the asset an attacker would prioritize, which fits a flaw that is already being exploited in the wild.

●  WHO IS EXPOSED TO CVE-2026-94127
One BIG-IP APM setting decides whether the CVSS 9.8 flaw is reachable.
NOT THE VULNERABLE CONFIGURATION
BIG-IP APM with no OAuth authorization-server profile on the virtual server (for example, SAML or standard access policies). CVE-2026-94127 is not reachable. Apply the hotfix on the normal patch cycle.
↓
THE VULNERABLE CONFIGURATION
APM configured as an OAuth authorization server issuing access tokens (an APM access policy plus an OAuth profile on one virtual server). An unauthenticated network attacker can send crafted traffic to the data plane, trigger the heap-based buffer overflow, and reach remote code execution. Actively exploited. Patch now.
Sources: F5 security advisory K000162605; Rapid7 analysis of CVE-2026-94127; CISA Known Exploited Vulnerabilities catalog.

The decision above is the whole triage in one view. If no virtual server pairs an APM access policy with an OAuth profile, this specific bug is not reachable, though the hotfix still belongs on the normal patch cycle. If that pairing exists on a device that terminates untrusted traffic, it is in the exploitable population and the hotfix is urgent, not optional.

The CISA Warning

CISA has amplified F5's warning, and the exploitation signal is not hypothetical. Both F5 and CISA state that CVE-2026-94127 is being actively exploited, which moves it out of the patch-when-convenient category and into the same urgency tier as any edge-device zero-day. Rapid7 reports that CVE-2026-94127 was added to CISA's Known Exploited Vulnerabilities (KEV) catalog as of September 22, 2026, while a publicly available proof of concept was not confirmed at the time of writing.

Confirmed exploitation with no public proof of concept is a familiar and uncomfortable shape for edge appliances. It means a working exploit is in at least one actor's hands but not yet on the open internet for commodity scanners to pick up and spray at scale. For federal civilian agencies, a KEV listing starts a remediation clock under CISA's binding operational directive framework. For everyone else, a KEV entry is the clearest available signal that a flaw deserves emergency handling rather than routine scheduling. The right reading of the quiet window before a public exploit lands is that it is time to patch and hunt calmly, not permission to defer.

What F5 BIG-IP APM Operators Should Verify

Start with the configuration question, because it sets the urgency for every device. Enumerate every BIG-IP virtual server and check whether an APM access policy and an OAuth profile are configured together. That pairing is the exposure condition, so any device with it goes to the front of the queue, and a device reachable from the internet or another untrusted network with that configuration is the worst case. A representative sample is not enough here; the answer can differ from one virtual server to the next.

Patch the exposed devices first. Apply the fixed engineering hotfix for the matching release train: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG for the 21.1.0 train, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG for 17.5.0, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG for 17.1.0, or a later build. Where a maintenance window genuinely cannot happen in the near term, request the F5 iRule workaround through a support case and apply it as a bridge, not a permanent substitute for the hotfix. Remember that Appliance mode does not cover you, so hardened devices still need the fix.

Then hunt, because active exploitation with no public proof of concept means the reasonable assumption for an exposed, unpatched device is that it may already have been reached. Prioritize post-compromise indicators on the affected data-plane systems: unexpected processes or shells on the BIG-IP host, configuration changes no one can account for, new or altered iRules, anomalous outbound connections from the appliance, and any tampering with the OAuth token-issuance path. Because remote code execution on a device that fronts authentication can lead to credential and access-token theft, extend the review to the identity flows that traverse the appliance and to the sessions and tokens it has issued. Patching closes the door. It does not tell you whether someone already walked through it.

This is the same discipline any vulnerability-management program applies to edge infrastructure, and it helps to tie this response to that broader practice rather than treating one CVE as a one-off. F5 BIG-IP has been a repeat target for a structural reason: it sits in the traffic path, terminates trust, and is exposed by design. The July 2026 round of F5 NGINX and BIG-IP patches was largely a verification exercise, with no exploitation reported at disclosure. This one is an incident-response exercise, because the exploitation is already happening.

Open Questions

Several things remain unconfirmed as of publication, and they shape how far the response should extend. No victims have been named, no threat actor has been publicly attributed, and the number of compromised APM instances is not known. A public proof of concept had not been confirmed at the time of F5's advisory and Rapid7's analysis, though that can change fast once a flaw is under active exploitation. For internet-facing appliances, the gap between confirmed exploitation and a commodity exploit is usually measured in days, so the prudent planning assumption is that the window is short.

What is not in question is enough to act on today: a CVSS 9.8 unauthenticated remote-code-execution flaw in F5 BIG-IP APM, exploitable when APM is configured as an OAuth authorization server issuing access tokens, actively exploited according to both F5 and CISA, with engineering hotfixes available now. For a zero-day in an edge device, that is a complete enough picture to move. For readers who want the conceptual grounding on why an actively exploited, unpatched flaw like this one is the sharpest category of risk, our explainer on zero-day exploit vs vulnerability vs attack lays out the timeline this CVE is sitting on right now.

Primary Documents