F5 BIG-IP APM RCE Vulnerability Exploited

F5 has confirmed active, unauthenticated exploitation of a critical F5 BIG-IP APM RCE vulnerability, tracked as CVE-2026-94127 (CVSS 9.8), affecting Access Policy Manager instances configured as OAuth Authorization Servers. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day F5 disclosed it, September 22, and gave federal agencies until Friday, September 25 to secure their networks.
What Happened
CVE-2026-94127 is a heap-based buffer overflow (CWE-122) in BIG-IP Access Policy Manager. It only affects virtual servers where an APM access policy and an OAuth profile are configured together, specifically where APM acts as an OAuth Authorization Server. Deployments using APM strictly as an OAuth client or resource server are not affected. Where the vulnerable configuration exists, an unauthenticated remote attacker can send specially crafted traffic to execute arbitrary code. F5 states in its own advisory, K000162605, published September 22, that it “learned that this vulnerability has been exploited,” a direct confirmation rather than a third-party inference. Affected versions are BIG-IP APM 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3. Fixes ship as ENG hotfixes for each branch. Internet-monitoring service Shadowserver currently counts more than 14,700 internet-facing IP addresses carrying BIG-IP APM fingerprints, with no visibility into how many are already patched.
F5 also published indicators of compromise: repeated OAuth authentication failures combined with suspicious command activity, followed by a Traffic Management Microkernel (TMM) process crash (SIGABRT). Unusually for a zero-day of this severity, F5 shipped an interim mitigation alongside the disclosure, an iRule that can be applied to the affected virtual server for organizations unable to install the hotfix immediately.
Why It Matters
BIG-IP APM is a widely deployed access and identity gateway in DACH enterprise environments, sitting in front of exactly the applications, VPNs and APIs an organization considers most sensitive. An unauthenticated RCE at that layer gives an attacker a foothold with visibility into whatever APM is meant to protect. The wider context is worth noting: F5 disclosed in October 2025 that state-sponsored hackers breached its own systems the previous August and stole undisclosed BIG-IP source code and vulnerability research. Neither F5 nor CISA has stated that CVE-2026-94127 originates from that theft, and DIESEC is not claiming a confirmed link here, but the pattern is a distinct governance risk in its own right: a security vendor’s breach can degrade the security of its products long after the incident itself has faded from the news, surfacing as a fresh zero-day a year later. CISA has flagged eight actively exploited F5 vulnerabilities since November 2021, four of which were later used in ransomware operations.
What You Should Do Now
- Check whether any BIG-IP APM virtual server in your environment has an access policy combined with an OAuth profile configured as an Authorization Server; if not, this specific flaw does not apply to that instance.
- Apply the ENG hotfix matching your branch (21.1.0.2.0.30.22, 17.5.1.9.0.160.12, or 17.1.3.5.0.41.14) as soon as possible; treat the September 25 CISA federal deadline as a practical benchmark even outside the US public sector.
- If immediate patching is not possible, apply F5’s interim iRule mitigation (referenced in Support article K000135931) to the affected virtual server without delay.
- Review logs for the published indicators of compromise: clusters of OAuth authentication failures, unusual command activity, and TMM process crashes (SIGABRT events) on affected devices.
DIESEC Perspective
This is the second time in under a year that an F5 flaw has combined maximum practical severity with a same-day exploitation confirmation from the vendor itself. Organizations that treat “no confirmed link to the 2025 F5 breach” as reassurance are missing the more useful lesson: a vendor breach is not a closed incident once the initial disclosure cycle ends, it can be a slow-burn source of future zero-days in exactly the products that breach touched.
Not sure whether your access and identity gateways still have unreviewed OAuth or SSO configurations left over from a prior deployment? Contact DIESEC for a rapid configuration and exposure review.
Sources: BleepingComputer | F5 Security Advisory K000162605
Published: 2026-09-24 | Category: Vulnerabilities & Patches | ~4 min read

