Published Wednesday, September 23, 2026 at 05:31 PM PT

<strong>F5 BIG-IP APM Zero-Day RCE Actively Exploited — Patch Now</strong>

BLUF: F5 has released a patch for CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager (APM) allowing unauthenticated remote code execution. Active exploitation in the wild confirmed. Organizations running vulnerable BIG-IP APM instances should patch immediately.

DETAILS

  • Vulnerability: CVE-2026-94127 — heap-based buffer overflow in F5 BIG-IP Access Policy Manager (APM)
  • Attack vector: Unauthenticated; attackers can send malicious traffic to achieve RCE without authentication
  • Active exploitation: Confirmed in-the-wild attacks; disclosed as zero-day with public exploits available
  • Affected component: F5 BIG-IP APM (particularly OAuth server deployments)
  • Patch status: F5 published security advisory and patches on 22 September 2026

IMPACT

Compromised BIG-IP APM instances could allow complete takeover of OAuth/access control infrastructure. Affected organizations include enterprises relying on BIG-IP APM for authentication and policy management—particularly identity providers, API gateways, and reverse proxies. An attacker gaining RCE on APM can bypass authentication, harvest credentials, redirect traffic, and pivot to downstream systems. Scope: any organization with unpatched BIG-IP APM in production.

RECOMMENDED ACTIONS

  1. Identify: Audit your environment for F5 BIG-IP APM instances. Check version against F5 advisory.
  2. Prioritize: Treat as emergency if APM is internet-facing or handles OAuth/SAML flows.
  3. Patch: Apply F5’s released fix immediately. If immediate patching is not possible, restrict network access to BIG-IP APM to trusted internal networks only.
  4. Monitor: Review logs for unusual traffic patterns, authentication bypasses, or failed RCE attempts (heap spray payloads).
  5. Coordinate: If you suspect compromise, isolate the system and initiate incident response.

SOURCES

  • F5 Security Advisory (CVE-2026-94127) — 22 September 2026
  • Rapid7, CSO Online, BleepingComputer, The Hacker News, SOC Prime, SecurityWeek

Recent high-severity events at publish time:

Recent high-severity events