{"id":208,"date":"2026-09-26T16:11:38","date_gmt":"2026-09-26T16:11:38","guid":{"rendered":"https:\/\/managedt.com\/blog\/f5-big-ip-apm-zero-day-cve-2026-94127\/"},"modified":"2026-09-26T16:11:39","modified_gmt":"2026-09-26T16:11:39","slug":"f5-big-ip-apm-zero-day-cve-2026-94127","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/f5-big-ip-apm-zero-day-cve-2026-94127\/","title":{"rendered":"F5 BIG-IP APM Zero-Day CVE-2026-94127 Under Active Attack"},"content":{"rendered":"<p>Network operators running F5 BIG-IP with Access Policy Manager configured as an OAuth Authorization Server now have a clear path to shut down active exploitation of a critical vulnerability that grants attackers remote code execution. The flaw, tracked as CVE-2026-94127, has been added to CISA&#8217;s Known Exploited Vulnerabilities catalog, and F5 has released hotfixes covering every affected release branch.<\/p>\n<h2>What is CVE-2026-94127?<\/h2>\n<p>CVE-2026-94127 is a critical-severity vulnerability in the BIG-IP Access Policy Manager (APM) module. It carries a CVSS score of 9.8 out of 10. The flaw allows unauthenticated attackers to send malicious traffic to a BIG-IP appliance and achieve remote code execution on the underlying system.<\/p>\n<p>According to F5&#8217;s advisory, the issue is reachable only when a BIG-IP APM access policy and an OAuth profile are configured together on a virtual server, and only when APM is configured as an OAuth Authorization Server. Deployments that use APM as an OAuth Client or Resource Server are not affected. Systems running in Appliance mode are also vulnerable. F5 described the bug as a data plane issue, meaning there is no control plane exposure, and the company discovered the defect internally.<\/p>\n<h2>Which BIG-IP versions are affected?<\/h2>\n<p>F5 lists three vulnerable release branches:<\/p>\n<ul>\n<li>BIG-IP APM 21.1.0<\/li>\n<li>BIG-IP APM 17.5.0 through 17.5.1<\/li>\n<li>BIG-IP APM 17.1.0 through 17.1.3<\/li>\n<\/ul>\n<p>No other F5 products are affected, according to the vendor. Hotfixes have been published for each of the three branches.<\/p>\n<h2>Why CISA added it to the KEV catalog<\/h2>\n<p>CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog at the same time F5 published its advisory. The catalog listing means federal civilian agencies are required to patch within three days under BOD 26-04. CISA&#8217;s KEV listing is widely used by private-sector organizations as a triage signal: any CVE added there has credible evidence of exploitation in the wild, not just a theoretical risk.<\/p>\n<h2>Indicators of compromise to watch for<\/h2>\n<p>F5 published three indicators of compromise and noted that their combined and frequent appearance should be correlated to an attack rather than each one being treated in isolation. Defenders running affected BIG-IP APM deployments should review logs and traffic records for these IoCs and investigate any matches promptly, especially on systems that have not yet been patched.<\/p>\n<h2>What to do now<\/h2>\n<p>The single most effective step is to apply the hotfix that matches the BIG-IP APM version in use. For environments that cannot patch immediately, the most practical compensating control is to remove the OAuth Authorization Server configuration from any virtual server that also carries an APM access policy, which closes the only known attack path F5 has described. After patching, review the published IoCs against historical logs to identify any prior compromise.<\/p>\n<h2>FAQ<\/h2>\n<h3>Which BIG-IP versions need patching for CVE-2026-94127?<\/h3>\n<p>BIG-IP APM 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3 are vulnerable. F5 has released hotfixes for each branch and says no other products are affected.<\/p>\n<h3>Has CVE-2026-94127 been exploited in the wild?<\/h3>\n<p>Yes. F5 confirmed exploitation in the wild and CISA added the CVE to its Known Exploited Vulnerabilities catalog on the same day, which triggers a three-day patching deadline for federal civilian agencies.<\/p>\n<h3>What configuration triggers CVE-2026-94127?<\/h3>\n<p>The bug is reachable when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, and only when APM is configured as an OAuth Authorization Server. Deployments using APM as an OAuth Client or Resource Server are not affected.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Which BIG-IP versions need patching for CVE-2026-94127?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"BIG-IP APM 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3 are vulnerable. F5 has released hotfixes for each branch and says no other products are affected.\"}},{\"@type\":\"Question\",\"name\":\"Has CVE-2026-94127 been exploited in the wild?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. F5 confirmed exploitation in the wild and CISA added the CVE to its Known Exploited Vulnerabilities catalog on the same day, which triggers a three-day patching deadline for federal civilian agencies.\"}},{\"@type\":\"Question\",\"name\":\"What configuration triggers CVE-2026-94127?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The bug is reachable when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, and only when APM is configured as an OAuth Authorization Server. Deployments using APM as an OAuth Client or Resource Server are not affected.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.securityweek.com\/critical-f5-big-ip-vulnerability-exploited-as-zero-day\/\" target=\"_blank\" rel=\"nofollow noopener\">securityweek.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>F5 and CISA warn that a critical BIG-IP APM flaw is being exploited in the wild. Affected versions and hotfixes are now available.<\/p>\n","protected":false},"author":3,"featured_media":207,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-208","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/208","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=208"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/208\/revisions"}],"predecessor-version":[{"id":209,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/208\/revisions\/209"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/207"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=208"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=208"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=208"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}