← Back to feed
Vulnerabilities & PatchesEmerging2 sourcesSep 23, 2026 · 07:17via BleepingComputer

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

Brief

F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it.

F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild.

The flaw can allow an unauthenticated attacker to execute arbitrary code on a vulnerable BIG-IP system. F5 disclosed the issue on September 22 and confirmed that exploitation had already been observed.

The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server. More specifically, the vulnerable configuration is one in which APM operates as an OAuth Authorization Server. Systems using APM only as an OAuth Client or Resource Server are not affected.

Read more on BleepingComputer

All credited sources

Highest-trust first. Dates are the publisher's original publish time.

BleepingComputerPrimary··trust 1.38

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. [... ]

Read more →
Security Affairs··trust 1.12

F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks

F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it.

F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild.

The flaw can allow an unauthenticated attacker to execute arbitrary code on a vulnerable BIG-IP system. F5 disclosed the issue on September 22 and confirmed that exploitation had already been observed.

The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server. More specifically, the vulnerable configuration is one in which APM operates as an OAuth Authorization Server. Systems using APM only as an OAuth Client or Resource Server are not affected.

“When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server.

Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. ( CVE-2026-94127 )” reads the advisory . “This vulnerability allows an unauthenticated attacker to perform RCE. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.

We have learned that this vulnerability has been exploited .”

F5 says the affected versions include BIG-IP 17. 1. 0 through 17. 1. 3, 17. 5. 0 through 17. 5. 1, and 21. 1. 0. The company has released hotfixes for the vulnerable branches. The flaw affects the data plane rather than the BIG-IP management plane, and F5 says the appliance mode is also vulnerable.

Read more →