Published Wednesday, September 23, 2026 at 05:32 PM PT

<strong>F5 BIG-IP APM Zero-Day Under Active Exploitation โ€” Immediate Patch Required</strong>

BLUF: F5 released a patch for CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager enabling unauthenticated remote code execution. The flaw is actively exploited in the wild; organizations running BIG-IP APM as an OAuth authorization server face immediate risk and must patch now.

DETAILS:

  • Vulnerability: CVE-2026-94127 โ€” unauthenticated remote code execution in F5 BIG-IP APM via heap buffer overflow
  • Attack vector: Malicious network traffic sent directly to BIG-IP instances configured as OAuth authorization servers; no credentials required
  • Exploitation status: Confirmed active exploitation occurring before patch availability
  • Patch release: F5 published security advisory and fixes on September 22, 2026
  • Affected scope: OAuth server deployments; standard BIG-IP APM instances in other configurations may not be impacted

IMPACT: Any F5 BIG-IP APM deployment functioning as an OAuth authorization server can be compromised remotely without authentication. Attack surface includes all internet-facing or network-accessible instances. Active exploitation means threat actors are already weaponizing this flaw.

RECOMMENDED ACTIONS:

  1. Immediate: Apply F5 security patch for CVE-2026-94127 to all BIG-IP APM systems, prioritizing OAuth servers
  2. If patching is delayed: Implement network access controls restricting traffic to BIG-IP APM from untrusted sources
  3. Detection: Monitor system logs and network traffic to OAuth endpoints for exploitation attempts (malformed requests, buffer overflow signatures)
  4. Validation: Verify patch installation and confirm OAuth servers are running patched versions before restoring normal traffic

SOURCES: F5 Security Advisory (Sept 22, 2026); CSO Online; The Hacker News; BleepingComputer; Rapid7; SecurityAffairs; SOC Prime; SecurityWeek


Recent high-severity events at publish time:

Recent high-severity events