F5 has warned that hackers are actively exploiting a critical zero-day vulnerability in BIG-IP Access Policy Manager (APM) deployments to execute code remotely without authentication.
Tracked as CVE-2026-94127, the flaw affects virtual servers configured with both an APM access policy and an OAuth profile, specifically where APM operates as an OAuth Authorization Server. F5 published advisory K000162605 on September 22, 2026, after learning that attackers had already weaponized the issue.
The vulnerability is a heap-based buffer overflow, categorized as CWE-122 and assigned internal tracking ID 2524777. Specially crafted network traffic can corrupt memory and enable arbitrary code execution on the BIG-IP system.
It carries a critical CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3, reflecting low attack complexity, network reachability, no privileges or user interaction, and potentially severe confidentiality, integrity, and availability consequences.
F5 BIG-IP OAuth Server 0-day Flaw
Importantly, exposure depends on configuration rather than the mere presence of APM. Deployments using APM only as an OAuth Client or Resource Server, without OAuth authorization-server profiles, are not affected. Appliance-mode systems remain vulnerable.
F5 said the vulnerability resides in the data plane, which processes application traffic, and does not expose the control plane. Consequently, restricting the management interface alone will not block exploitation reaching an affected virtual server.
Known vulnerable releases include BIG-IP APM 21.1.0, versions 17.5.0 through 17.5.1, and versions 17.1.0 through 17.1.3. Other BIG-IP modules, BIG-IQ Centralized Management, BIG-IP Next, F5 Distributed Cloud services, NGINX products, F5OS variants, and F5 AI Gateway were evaluated as unaffected.
F5 cautions that releases beyond End of Technical Support are not evaluated, so administrators should not interpret their absence from the affected list as evidence of safety.
Engineering hotfixes are available as Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso for their respective branches.
Organizations should inventory BIG-IP APM virtual servers, identify the vulnerable access-policy and OAuth-profile combination, and install the applicable hotfix immediately. Where emergency patching is operationally impossible, customers can contact F5 Support for an iRule that temporarily mitigates attacks against the affected virtual server.
Defenders should also hunt for evidence of attempted or successful exploitation. F5 advises investigating three events occurring close together: repeated OAuth authentication failures, suspicious command execution, and a subsequent Traffic Management Microkernel (TMM) SIGABRT event.
Ten or more invalid-token messages in /var/log/apm deserve review, particularly when originating from one IP address. Analysts can inspect failure counts with tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed and correlate timestamps with entries in /var/log/audit.
A TMM core file can appear when TMM enters a loop, and the SOD daemon issues SIGABRT, but neither a core file nor an authentication failure independently proves compromise. Their frequency and temporal relationship matter.
CISA has added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog following evidence of in-the-wild attacks, reinforcing the need for urgent remediation.
F5 discovered the vulnerability internally, while public reporting has not established an attacker identity, exploitation scale, or confirmed post-compromise objectives.
Security teams should preserve logs, review suspicious activity around observed failures, and prioritize exposed OAuth Authorization Server configurations in incident response. That uncertainty makes retrospective threat hunting as important as closing the immediate exposure now.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

