Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
F5 has confirmed active exploitation of CVE-2026-94127, a zero-day vulnerability in the BIG-IP APM module. The flaw allows unauthenticated remote code execution via a heap-based buffer overflow. CISA added the vulnerability to the KEV catalog on September 22, 2026, setting two deadlines for September 25, 2026 for federal agencies.
- CVE-2026-94127 carries a CVSS score of 9.8 (3.1) and 9.3 (4.0): unauthenticated remote attack with no user interaction via heap-based buffer overflow (CWE-122).
- The trigger condition is precise: a virtual server with an APM access policy and an OAuth profile in Authorization Server mode; deployments using APM solely as a Client or Resource Server are not vulnerable.
- CISA invoked BOD 26-04 with mandatory forensic triage: FCEB agencies must document intrusion detection by September 25, 2026.
- Shadowserver tracks over 14,700 IP addresses with a BIG-IP APM fingerprint exposed to the internet; the patch status of these systems is unknown.
The Configuration That Exposes RCE
The flaw resides in the BIG-IP APM data plane, not the control plane. The attack traverses traffic directed at virtual servers configured as OAuth Authorization Servers. The buffer overflow occurs during the processing of OAuth requests on these specific endpoints.
According to the F5 advisory cited by BleepingComputer, vulnerable configurations combine three elements: an active APM module, an access policy on the virtual server, and an OAuth profile in Authorization Server mode. Organizations using BIG-IP APM exclusively as a Client or Resource Server — without authorization server profiles — are not exposed.
Systems in Appliance mode are also vulnerable. The data/control plane boundary limits post-compromise escalation vectors but does not block the initial remote execution.
CVSS 9.8 and Convergence of Official Sources
NVD and CVE.org records agree on critical parameters. CVSS 3.1 base score: 9.8, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. CVSS 4.0 base score: 9.3, vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. Both confirm network attack vector, low complexity, no privileges required, no user interaction, and maximum impact on confidentiality, integrity, and availability.
HOL.org reported the CWE-122 classification and the distinction: "This is a data-plane bug; the control plane is not the exposure." The convergence among the F5 advisory, official CVE records, and independent analysis confirms the nature and severity of the flaw.
Affected versions span three branches: 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3. F5 released specific hotfixes: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG. End of Technical Support products were not evaluated for patch availability.
"We have learned that this vulnerability has been exploited" — F5 security advisory
Attack Surface: Over 14,700 IPs Tracked
Shadowserver detects over 14,700 IP addresses with a fingerprint attributable to BIG-IP APM exposed on the internet. This figure indicates IPs with a service fingerprint, not confirmed vulnerable systems; the detection technique does not distinguish between OAuth Authorization Server configurations, OAuth Client/Resource Server configurations, or the absence of the APM module.
The geographic distribution and sector of exposed systems were not detailed in available sources. It remains unknown how many of the 14,700 IPs fall within the blast radius of the vulnerable configuration.
Mandatory Forensic Triage: The Weight of BOD 26-04
The CISA KEV entry for CVE-2026-94127 specifies "forensic triage required" as an additional requirement beyond patching. This raises the operational cost even for organizations that apply the update by the September 25, 2026 deadline. Forensic triage requires documented intrusion detection activity.
The CISA alert of September 22, which added four vulnerabilities to the KEV catalog, states: "These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise."
For federal agencies covered by BOD 26-04, September 25, 2026 is the deadline for patching or forensic triage. For the private sector, the same date serves as a benchmark for due diligence assessment.
Immediate Actions
Priority actions derived from verified sources:
- Verify via tmsh whether virtual servers exist that combine an APM access policy and an OAuth profile in Authorization Server mode: specific commands are documented in the HOL.org analysis.
- Apply the ENG hotfixes for the version in use, or the temporary mitigation via iRule provided by F5 for those unable to patch immediately.
- Conduct documented forensic triage if within the BOD 26-04 perimeter: CISA requires evidence of intrusion detection, not just patch application.
- Monitor logs for multiple OAuth authentication failures, suspicious commands, and TMM SIGABRT: confirmed indicators of compromise from F5 and HOL.org sources.
Analysis: The Risk Profile in the F5 Context
Since November 2021, CISA has flagged eight F5 vulnerabilities in the KEV catalog, four of which also appeared in ransomware campaigns. This historical data indicates F5 infrastructure is a recurring target, but does not establish that CVE-2026-94127 is used in ransomware: the CISA KEV lists "Unknown" for this specific flaw.
The absence of independent primary sources on active exploitation beyond vendor confirmation is a limitation of this reconstruction. The SolarWinds source (Source 2) is excluded from the brief and does not appear in the body.
The reconstruction relies on the F5 advisory, official CVE records, and HOL.org technical analysis. No independent primary sources on active exploitation are available beyond vendor confirmation.
Information has been verified against cited sources and is current as of publication.
Sources
- https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/
- https://radar.offseq.com/threat/f5-patches-big-ip-apm-zero-day-flaw-exploited-in-rce-attacks-191545153729ae57
- https://hol.org/blog/cve-2026-94127-f5-big-ip-apm-oauth-rce-kev
- https://nvd.nist.gov/vuln/detail/CVE-2026-94127
- https://www.cve.org/CVERecord?id=CVE-2026-94127
- https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-94127
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.