F5 released emergency engineering hotfixes on September 22 for CVE-2026-94127, a critical BIG-IP Access Policy Manager vulnerability that can give an unauthenticated remote attacker code execution on affected appliances. F5 has confirmed that the flaw has already been exploited in the wild.
The vulnerability carries a CVSS v3.1 score of 9.8 and affects specific BIG-IP APM deployments configured as OAuth Authorization Servers. Exploitation reaches the data plane rather than the management interface, making the configuration of application-facing virtual servers central to determining exposure.
Malicious OAuth Traffic Can Trigger Remote Code Execution
CVE-2026-94127 is a heap-based buffer overflow in BIG-IP APM. According to F5’s advisory, specially crafted traffic can lead to remote code execution when an APM access policy and an OAuth profile are configured on the same virtual server.
The vulnerable configuration is narrower than all BIG-IP APM installations. Deployments using APM strictly as an OAuth Client or Resource Server, without OAuth Authorization Server profiles, are not affected by this vulnerability. BIG-IP systems operating in Appliance mode can still be vulnerable.
The distinction between data-plane and control-plane exposure is also operationally important. F5 says CVE-2026-94127 is a data-plane issue and does not expose the control plane. Restricting access to the BIG-IP management interface therefore does not by itself remove exposure from a vulnerable application-facing virtual server.
Affected BIG-IP APM Releases
F5 has made engineering hotfixes available for the affected supported branches. CERT-EU and the Canadian Centre for Cyber Security independently published the same affected-version and remediation information following F5’s disclosure.
| BIG-IP APM branch | Affected releases | Engineering hotfix |
|---|---|---|
| 21.1.x | 21.1.0 before the engineering hotfix | Hotfix-BIGIP-21.1.0.2.0.30.22-ENG |
| 17.5.x | 17.5.0 through 17.5.1 before the engineering hotfix | Hotfix-BIGIP-17.5.1.9.0.160.12-ENG |
| 17.1.x | 17.1.0 through 17.1.3 before the engineering hotfix | Hotfix-BIGIP-17.1.3.5.0.41.14-ENG |
F5 notes that software versions that have reached End of Technical Support were not evaluated. Their absence from the supported affected-version list should therefore not be interpreted as confirmation that older deployments are safe.
F5 Confirms Exploitation in the Wild
The vulnerability was discovered internally by F5, but the company says it subsequently learned that the flaw had been exploited. Public reporting has not established the identity of the attackers, the number of compromised organizations or their post-compromise objectives.
CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog on September 22. The Canadian Centre for Cyber Security and CERT-EU also issued alerts urging organizations to remediate affected BIG-IP APM systems.
The combination of confirmed exploitation, network reachability and unauthenticated code execution makes vulnerable application-facing deployments a priority for infrastructure teams. Operators should assess configuration rather than relying only on software inventory, because the flaw depends on APM and OAuth Authorization Server functionality being configured together.
What Operators Should Hunt For
Patching closes the vulnerable path, but F5 also provides guidance for determining whether a system may already have been targeted. The vendor recommends correlating repeated OAuth authentication failures with suspicious command execution and a subsequent Traffic Management Microkernel, or TMM, SIGABRT event.
Repeated invalid-token messages in /var/log/apm warrant review, particularly when ten or more originate from the same IP address within a short period. Administrators can also inspect OAuth failure statistics and correlate suspicious timestamps with activity recorded in /var/log/audit.
A TMM core file or an authentication failure alone does not establish compromise. F5’s guidance focuses on the sequence and timing of multiple indicators, which should trigger human investigation and the organization’s normal incident-response process.
What Happens Next
Organizations running BIG-IP APM should first determine whether any virtual server combines an APM access policy with an OAuth Authorization Server profile. Affected systems should receive the appropriate engineering hotfix as soon as operational testing permits.
Where immediate patching is not possible, F5 customers can obtain an iRule mitigation from F5 Support for affected virtual servers. CERT-EU additionally recommends preserving forensic evidence before remediation and beginning incident response if indicators of compromise are identified.
F5 has not publicly disclosed the scale or attribution of the exploitation. Until more information becomes available, the confirmed facts are that exploitation has occurred, supported vulnerable branches now have engineering hotfixes, and affected operators have both remediation and compromise-assessment guidance available.







