Vulnerabilities · 1h ago

F5 BIG-IP APM Zero-Day Is Being Exploited

CSIRT Italia, NCSC-NL, and CERT-EU said F5 BIG-IP Access Policy Manager (APM) is being actively exploited in the wild through CVE-2026-94127, a heap-based buffer overflow that can lead to remote code execution. F5’s fixes cover only BIG-IP APM systems with a virtual server that has both an access policy and an OAuth profile.

Attackers send specially shaped traffic into the OAuth login path, which can make the device write past the end of a memory buffer. On an exposed APM instance, that corruption can be turned into code execution before authentication succeeds, so the issue is not just “BIG-IP” in general but the specific management flow that handles login and policy.

For operators, the lasting question is which APM virtual servers actually have that configuration and whether exploitation already left signs behind. Where that setup exists, patching changes the device’s future state; it does not by itself answer whether the box was already used as the entry point.

CVE-2026-94127

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: when a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious traffic…

CISA federal remediation date Sep 25

Timeline

Sources

4 sources covering this story

Entities

Vendor digest: F5

Part of the PlainSec briefing for 2026-09-22

Editions

Related stories