F5 has released an emergency fix for CVE-2026-94127, a critical zero-day vulnerability in BIG-IP Access Policy Manager (APM) that is being actively exploited. The flaw allows unauthenticated attackers to execute code remotely on systems configured as OAuth authorization servers.
With a CVSS score of 9.8 under v3.1 and 9.3 under v4.0, this issue demands the highest response priority. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026, confirming that exploitation is no longer merely theoretical.
Not Every BIG-IP APM System Is Affected
According to F5, the affected condition is specific: BIG-IP APM must operate as an OAuth Authorization Server, with an access policy and an OAuth authorization server profile attached to the same virtual server. Malicious traffic sent to that virtual server can trigger a heap-based buffer overflow and lead to code execution.
Deployments using APM only as an OAuth Client or Resource Server, without an authorization server profile, are not within the confirmed affected scope. However, versions that have reached the end of technical support were not evaluated by F5 and should not be assumed safe.

Published Affected Versions and Fixes
Branch 21.1 is affected at version 21.1.0 before Hotfix-BIGIP-21.1.0.2.0.30.22-ENG. Branch 17.5 includes versions 17.5.0 through 17.5.1 before Hotfix-BIGIP-17.5.1.9.0.160.12-ENG. Branch 17.1 includes versions 17.1.0 through 17.1.3 before Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.
This list should be checked against the latest notice in the F5 support portal because an engineering hotfix may be replaced or incorporated into a later release. Administrators should verify the exact build number rather than looking only at the major version branch.
Why Restricting the Management Interface Is Not Enough
Exploit traffic reaches the virtual server providing OAuth services and does not necessarily pass through the BIG-IP management interface. Restricting the management interface to an internal network or trusted IP list therefore does not remove the risk. F5 also confirms that systems running in Appliance mode can be affected.
This is important because many organizations treat isolation of the management port as their primary safeguard. For CVE-2026-94127, the attack surface is the business service accepting OAuth requests from the network, so the virtual server configuration and software themselves must be addressed.
Indicators of Compromise to Review
F5 recommends investigation when a sequence of repeated OAuth authentication failures, suspicious commands in audit logs, and a TMM SIGABRT shortly afterward is observed. In APM logs, administrators may find repeated failed UserInfo requests with the message “The access token is invalid.”
One reference signal is 10 or more requests from the same IP address within a short period, but this threshold should not be used as the sole condition. An unusual rise in total_failed OAuth statistics, unfamiliar commands in /var/log/audit, and TMM core files should be correlated on the same timeline.
Priority Response Steps
- Inventory assets: identify every BIG-IP APM system, version, build, virtual server, and active OAuth role.
- Preserve evidence: back up logs and investigative data before changing the system when suspicious indicators are found.
- Install the hotfix: apply the correct engineering hotfix for the branch following F5 guidance, test it, and confirm normal OAuth operation.
- Apply temporary mitigation: if immediate patching is not possible, contact F5 Support for the mitigation iRule for the affected virtual server.
- Investigate after patching: the patch prevents new exploitation but does not prove the system was never compromised or remove access already established.
The Response Window Is Very Short
F5 published its advisory on September 22, 2026 and confirmed known exploitation. CISA added CVE-2026-94127 to KEV the same day. U.S. federal civilian agencies were required to apply mitigation by September 25 and then install the vendor’s final patch as soon as possible.
The urgent timeline reflects the risk posed by a device at the network edge that controls access to enterprise applications. Shadowserver observed more than 14,700 IP addresses with BIG-IP APM fingerprints on the Internet, although this figure does not show how many actually use the vulnerable OAuth configuration.
“Patched” Should Not Be Equated With “Safe”
If logs show a behavior chain matching F5 indicators, the organization should activate full incident response: isolate as appropriate, determine which commands ran, review persistence mechanisms, accounts, keys, and potentially exposed credentials, and inspect downstream systems.
Recovery should be based on device trust and forensic evidence, not only on hotfix status. BIG-IP APM operators should also increase OAuth traffic monitoring, alert on unusual authentication failures, and limit public exposure to what is strictly necessary.
Management Lessons From CVE-2026-94127
The incident shows that configuration inventory is as important as version inventory. Two systems running the same BIG-IP APM release may have different risk depending on their OAuth role. Asset data should therefore describe enabled modules, virtual servers, profiles, and functions.
The immediate priority is to identify systems acting as OAuth Authorization Servers, preserve evidence, apply the iRule if needed, and install the correct hotfix. In parallel, security teams should hunt for compromise rather than wait for more campaign details.
VNCyberS compiled from F5, CISA, The Hacker News, and BleepingComputer















