F5 BIG-IP APM Zero-Day CVE-2026-94127 Was Exploited Before Its Hotfix
Security / news
F5 BIG-IP APM Zero-Day CVE-2026-94127 Was Exploited Before Its Hotfix
Only APM servers running an OAuth profile as an Authorization Server are exposed, but F5 says attackers already found them.

An unauthenticated attacker with network access can run code on an F5 BIG-IP Access Policy Manager (APM) by sending crafted traffic, provided the virtual server has both an APM access policy and an OAuth profile attached. F5 has confirmed the flaw, CVE-2026-94127, was exploited before its fix.
CISA added it to the Known Exploited Vulnerabilities catalog on September 22. The Register reported F5's own wording: "We have learned that this vulnerability has been exploited."
Check for the configuration first, then install the hotfix for your branch. F5 Support has published an iRule workaround for sites that cannot patch yet.

Which BIG-IP versions are affected
Rapid7's analysis lists three affected branches, each with an engineering hotfix.
| Branch | Vulnerable before | Fixed in |
|---|---|---|
| BIG-IP 21.1.0 | Hotfix-BIGIP-21.1.0.2.0.30.22-ENG | that hotfix or later |
| BIG-IP 17.5.0 | Hotfix-BIGIP-17.5.1.9.0.160.12-ENG | that hotfix or later |
| BIG-IP 17.1.0 | Hotfix-BIGIP-17.1.3.5.0.41.14-ENG | that hotfix or later |
The flaw is a heap-based buffer overflow. Rapid7 says it lives in the data plane, not the control plane, and that Appliance mode systems are affected.
The score depends on who is counting
Rapid7 gives CVSS 9.8. The Register gives 9.3. The two are most likely different scoring versions, though neither article says so, and F5's own advisory was not among the pages fetched for this report.
The score says nothing about how many devices qualify. Only virtual servers with an access policy and an OAuth profile on the same listener match the condition Rapid7 describes, and The Register adds that the box must be acting as an OAuth Authorization Server. A BIG-IP running APM for other purposes is not in scope, so the first job is a configuration audit, not a mass reboot.
Dates and disagreements
Rapid7 dates F5's disclosure to September 22. The Register says F5 released its patch on Tuesday, September 23, and that CISA listed the flaw the same day. CISA's own alert is dated September 22. The gap is probably a matter of time zones or of advisory versus patch availability, and it is not resolved in the sources.
| Item | Detail |
|---|---|
| Public exploit code | None confirmed at disclosure, per Rapid7 |
| Federal deadline | A Friday, per The Register, which is September 25 |
| Victim count | Not disclosed by F5 |
| Ransomware involvement | Not disclosed by F5 |
What is not known
F5 did not say how many systems were compromised, who exploited the bug, or whether ransomware was involved, according to The Register. It notes that the advisory follows a 2025 incident in which nation-state actors breached F5's network and took source code and details of undisclosed flaws. It also recalls that Google's Mandiant tied an older F5 bug, CVE-2023-46747, to a group it calls UNC5174, assessed to operate from China. Neither source links CVE-2026-94127 to either event, and this report does not either.
For other patch-window stories, see the LuaRocks sandbox escape and the UK AI Security Institute tests on supply-chain attacks.
The federal deadline of September 25 has passed.
Sources
More in Security
- 01NVIDIA's OpenShell Agent Sandbox Hits 14,400 Stars: What It Enforces and What It Leaves OutThe Apache 2.0 runtime confines agents with Landlock and seccomp, but its own issue tracker and an outside critique show where the boundary stops.
- 02Linux Kernel Nears 2,000 CVEs Per Release as AI Bug Reports Pile UpGreg Kroah-Hartman's figures show a fourfold jump from the 6.x series, while one vendor's count puts real exploitation signal at 1 in 400.
- 03Apple Says macOS Full Disk Access Will Require 'Very Explicit User Action'An October 2 developer post cites AI agents as the reason, but gives no macOS version, no date and no list of affected apps.
- 04Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.