F5 Patches Critical BIG-IP APM Zero-Day Exploited for RCE
F5 has released hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in BIG-IP APM. The flaw, a heap-based buffer overflow with a CVSS score of 9.8, allows unauthenticated remote code execution on systems where APM serves as an OAuth authorization server.

Attackers are actively exploiting a critical zero-day vulnerability in F5's BIG-IP Access Policy Manager (APM) module. The flaw, tracked as CVE-2026-94127, enables unauthenticated remote code execution (RCE) on affected BIG-IP systems.
F5 disclosed the vulnerability in an advisory on September 22. The company states the flaw only impacts configurations where APM is specifically serving as an OAuth authorization server, which issues access tokens to applications. The vulnerable setup involves having both an APM access policy and an OAuth authorization server profile on the same virtual server.
Vulnerability Details and Impact
The flaw is a heap-based buffer overflow. F5 rates it a critical 9.8 out of 10 on the CVSS v3.1 scale and 9.3 on CVSS v4.0. Because exploitation involves sending malicious traffic directly to the configured virtual server, standard protections like restricting access to the BIG-IP management interface are ineffective. Systems running in Appliance mode are also vulnerable.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog on September 22. CISA directed federal civilian agencies to apply F5's mitigations by September 25 under a binding operational directive issued in June.
Affected Versions and Mitigations
F5 has released engineering hotfixes for affected software branches. The vulnerability is present only when APM acts as an OAuth authorization server. Systems using APM solely as an OAuth client or resource server are not affected.
| BIG-IP APM Branch | Affected Versions | Engineering Hotfix |
|---|---|---|
| 17.1.x | 17.1.0 - 17.1.2 | Hotfix-BIGIP-17.1.2.1.0.60.6-ENG |
| 17.5.x | 17.5.0 - 17.5.1.2 | Hotfix-BIGIP-17.5.1.2.1.0.60.6-ENG |
| 21.0.x | 21.0.0 - 21.0.1 | Hotfix-BIGIP-21.0.1.1.0.60.6-ENG |
F5 notes that versions which have reached End of Technical Support were not evaluated, leaving their status unknown. The company also clarified that systems previously patched for another APM flaw, CVE-2025-53521, are still vulnerable to this new attack if configured as an OAuth authorization server.
For organizations unable to install the hotfix immediately, F5 offers an iRule mitigation. Customers must open a support ticket to obtain it. CISA advised agencies to apply the iRule first "to allow for proactive forensic triage," and then install the vendor patch.
Indicators of Compromise and Response
CERT-EU, the cybersecurity service for EU institutions, published an advisory detailing signs of potential exploitation. The indicators are based on F5's guidance. A combination of repeated OAuth authentication failures, followed by suspicious commands, and then a TMM SIGABRT signal shortly after should trigger a full forensic review.
Key logs to examine include the APM log for repeated failed UserInfo requests with the error "The access token is invalid," particularly from a single IP address. Administrators should also check the OAuth counter for an unexplained rise in total_failed and review the audit log for suspicious commands executed around the time of those failures.
CERT-EU recommends a response sequence: preserve forensic evidence, apply the available hotfix, check for signs of compromise, and initiate incident response if any are found. Neither F5's CVE record nor the advisories from CISA and CERT-EU specify whether applying the hotfix removes any persistent access an attacker may have already gained.





