F5 has disclosed that attackers are actively exploiting CVE-2026-94127, a critical vulnerability in certain BIG-IP Access Policy Manager deployments. The flaw can allow an unauthenticated attacker to execute code on a vulnerable BIG-IP system by sending malicious traffic to an affected virtual server.
What is confirmed
F5 says it has learned that CVE-2026-94127 has been exploited in the wild. SecurityWeek and BleepingComputer reported on September 23 that F5 released engineering hotfixes after disclosing the issue. The vulnerability carries a CVSS v3.1 score of 9.8.
The affected configuration is specific: BIG-IP APM must have an access policy and an OAuth authorization server profile configured on the same virtual server. F5 says deployments using APM strictly as an OAuth Client or Resource Server, without OAuth authorization server profiles, are not affected by this vulnerability.
Why CVE-2026-94127 is urgent
The vulnerability is especially serious because exploitation does not require authentication. A remote attacker able to send crafted traffic to a vulnerable deployment may be able to achieve remote code execution on the BIG-IP system.
CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. That designation is a strong signal for organizations to prioritize remediation rather than treating the issue as a routine patch-cycle item.
Which BIG-IP deployments are affected
According to F5 reporting summarized by SecurityWeek, affected releases include BIG-IP APM 21.1.0, versions 17.5.0 through 17.5.1, and versions 17.1.0 through 17.1.3 when the vulnerable OAuth authorization server configuration is present. Administrators should verify their exact version and configuration against current F5 guidance before assuming a system is safe.
What organizations should do now
Administrators running BIG-IP APM should immediately determine whether any virtual server combines an APM access policy with an OAuth authorization server profile. If so, apply the engineering hotfix or other remediation provided by F5 as quickly as operationally possible.
Organizations should also review F5’s published indicators of compromise, inspect relevant BIG-IP telemetry for suspicious activity, preserve logs for investigation, and treat evidence of unexpected code execution or unusual traffic as a potential incident. Because exploitation has already been observed, patching alone should not replace a review for prior compromise.
What remains unknown
Public reporting has not established the identity of the attackers, the number of organizations compromised, or the full scope of activity associated with exploitation. Those details should not be inferred from the existence of the vulnerability alone.
Why this matters beyond F5 customers
Internet-facing access infrastructure is a high-value target because compromise can provide attackers a path toward applications and internal resources. Organizations should maintain an inventory of exposed edge systems, monitor vendor security advisories, and have an emergency process for vulnerabilities confirmed to be under active exploitation.
Sources
SecurityWeek: Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
BleepingComputer: F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks