Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
F5 Networks disclosed CVE-2026-94127 on September 22, 2026, a critical vulnerability in the BIG-IP APM module actively exploited as a zero-day before patches were available. The National Vulnerability Database assigns a CVSS 3.1 score of 9.8. The same day, the Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog with a remediation deadline of September 25: three days, a window drastically shorter than the traditional 14- to 21-day periods. The decision signals that zero-days in access edge infrastructure are treated as emergencies, not routine vulnerabilities.
- CVE-2026-94127 is a heap-based buffer overflow (CWE-122) in the BIG-IP APM data plane when configured as an OAuth Authorization Server: unauthenticated remote attack with arbitrary code execution.
- The vulnerability affects BIG-IP versions 17.1.0-17.1.3, 17.5.0-17.5.1, and 21.1.0; specific hotfixes are available for each branch.
- F5 and CISA confirm active exploitation at the time of disclosure; CISA imposed a three-day deadline on federal civilian agencies.
- Shadowserver detected more than 14,700 IP addresses of Internet-exposed BIG-IP APM systems, without distinguishing between patched and vulnerable configurations.
The Mechanism: Why Only Certain Configurations Are at Risk
The flaw resides in the data plane, not the control plane: attackers do not target the management interface but the user-traffic data path. The trigger condition is specific and configuration-dependent. According to advisory K000162605 cited by Security Affairs, the vulnerability manifests "when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server." F5 clarifies that the condition occurs exclusively when BIG-IP APM acts as an OAuth Authorization Server; deployments using APM strictly as an OAuth Client or Resource Server, without Authorization Server profiles, are not affected.
The bug is classified as CWE-122 (heap-based buffer overflow). An unauthenticated remote attacker sends crafted traffic that overwrites heap memory regions, achieving arbitrary code execution. The F5 advisory, reported by Security Affairs, states that systems in Appliance mode are also vulnerable: the deployment mode does not mitigate the issue.
Exploitation Confirmation and Warning Signs
F5 stated verbatim that it learned the vulnerability "has been exploited." On the same disclosure day, CISA added CVE-2026-94127 to its KEV catalog, activating Binding Operational Directive 26-04, which requires federal civilian agencies to complete remediation by September 25, 2026. The CISA quote reported by BleepingComputer describes these vulnerabilities as "a frequent attack vector for malicious actors" that "pose significant risks to the federal enterprise."
Indicators of compromise published by F5 include repeated OAuth authentication failures, suspicious commands, and SIGABRT events in the Traffic Management Microkernel (TMM). No public details are available on specific campaigns, identified threat actors, or the geographic distribution of compromised systems.
Internet Exposure and Profile of Affected Systems
Shadowserver data, reported by BleepingComputer, indicates more than 14,700 IP addresses of Internet-reachable BIG-IP APM systems. This figure does not distinguish between systems with the vulnerable configuration (active OAuth Authorization Server) and those with other configurations, nor between patched and unpatched instances. The data measures attack-surface exposure, not the actual vulnerability rate.
F5 serves more than 23,000 global customers, including 48 of the Fortune 50. The product's prevalence in enterprise access infrastructure amplifies the blast radius of a compromise: a breached access edge appliance enables lateral movement, single sign-on bypass, and propagation within federated architectures.
The Remediation Window: Hotfixes and Temporary Mitigation
F5 released branch-specific hotfixes for three version lines: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG for version 21.1.0, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG for 17.5.1, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG for 17.1.3. The CVE.org source lists these exact build identifiers.
For organizations unable to apply the hotfix immediately, F5 provides a temporary mitigation via iRule, accessible through the support portal. The iRule implements OAuth traffic inspection to block known malicious patterns. The source does not specify whether installing the hotfix removes previously established access by threat actors.
"When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server." — F5 security advisory K000162605, via Security Affairs
Immediate Actions
- Verify whether any virtual servers with an active OAuth Authorization Server profile exist in the BIG-IP APM inventory: only these configurations expose the flaw.
- Apply the corresponding version-specific hotfix (21.1.0.2.0.30.22-ENG, 17.5.1.9.0.160.12-ENG, or 17.1.3.5.0.41.14-ENG) based on the installed branch.
- For instances where the hotfix cannot be applied immediately, request the temporary mitigation iRule through the F5 support portal and monitor logs for TMM SIGABRT events.
- Check OAuth authentication logs for anomalies: repeated authentication failures or suspicious command patterns indicate possible ongoing compromise.
CISA Deadline Compression: A Policy Signal
The three-day interval imposed by CISA marks a sharp deviation from the standard 14- to 21-day windows for critical vulnerabilities. The choice reflects an operational redefinition: access infrastructure zero-days are classified as emergency incidents regardless of the specific exploitation context. For the private sector with comparable exposure, the federal deadline serves as an indicator of the effective time available before automated exploit weaponization makes patching a belated measure.
Historical context supports this temporal compression. Since November 2021, CISA has tracked eight actively exploited F5 vulnerabilities; four were used in ransomware campaigns. The recurrence of zero-days in the BIG-IP codebase suggests that criminal and state actors possess mature analysis and exploitation capabilities for this platform.
The dossier does not identify the actor behind the current exploitation of CVE-2026-94127, nor does it confirm the existence of a public proof-of-concept or active ransomware campaigns leveraging this specific flaw. The technical reading suggests that the configuration-scoped vulnerability, limited to OAuth Authorization Server, offers a narrower surface than initially appeared: the original CVE record, updated at 00:45 UTC on September 23, 2026, was narrowed to exclude other OAuth profiles.
Sources
- https://tech-insider.org/f5-big-ip-apm-zero-day-cve-2026-94127-2026/
- https://www.hendryadrian.com/critical-f5-big-ip-vulnerability-exploited-as-zero-day/
- https://securityaffairs.com/199619/security/f5-big-ip-apm-zero-day-exploited-in-zero-day-rce-attacks.html
- https://www.cve.org/CVERecord?id=CVE-2026-94127
- https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/
- https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.