Published Wednesday, September 23, 2026 at 05:32 PM PT

BLUF: F5 released a patch for CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager enabling unauthenticated remote code execution. The flaw is actively exploited in the wild; organizations running BIG-IP APM as an OAuth authorization server face immediate risk and must patch now.
DETAILS:
- Vulnerability: CVE-2026-94127 โ unauthenticated remote code execution in F5 BIG-IP APM via heap buffer overflow
- Attack vector: Malicious network traffic sent directly to BIG-IP instances configured as OAuth authorization servers; no credentials required
- Exploitation status: Confirmed active exploitation occurring before patch availability
- Patch release: F5 published security advisory and fixes on September 22, 2026
- Affected scope: OAuth server deployments; standard BIG-IP APM instances in other configurations may not be impacted
IMPACT: Any F5 BIG-IP APM deployment functioning as an OAuth authorization server can be compromised remotely without authentication. Attack surface includes all internet-facing or network-accessible instances. Active exploitation means threat actors are already weaponizing this flaw.
RECOMMENDED ACTIONS:
- Immediate: Apply F5 security patch for CVE-2026-94127 to all BIG-IP APM systems, prioritizing OAuth servers
- If patching is delayed: Implement network access controls restricting traffic to BIG-IP APM from untrusted sources
- Detection: Monitor system logs and network traffic to OAuth endpoints for exploitation attempts (malformed requests, buffer overflow signatures)
- Validation: Verify patch installation and confirm OAuth servers are running patched versions before restoring normal traffic
SOURCES: F5 Security Advisory (Sept 22, 2026); CSO Online; The Hacker News; BleepingComputer; Rapid7; SecurityAffairs; SOC Prime; SecurityWeek
Recent high-severity events at publish time:

