F5 patches a BIG-IP APM flaw already exploited against OAuth servers
EditorialBy TrustList Editorial
CVE-2026-94127 lets an unauthenticated attacker run code on BIG-IP APM systems acting as an OAuth authorisation server. It is being exploited, and US federal agencies were given until 25 September to fix it.
About F5 patches a BIG-IP APM flaw already exploited against OAuth servers
F5 patches a BIG-IP APM flaw already exploited against OAuth servers
22 September 2026 — F5 has released fixes for a critical flaw in BIG-IP Access Policy Manager (APM) that attackers are already exploiting. Tracked as CVE-2026-94127, it is a heap-based buffer overflow: an attacker with network access to an affected virtual server can use it to run code on the device without logging in. F5 published advisory K000162605 on 22 September 2026, and the US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalogue the same day, with a deadline of 25 September for federal civilian agencies.
What changes
The flaw is rated 9.8 out of 10 on the CVSS 3.1 scale, but it is not exposed in a default set-up. A system is at risk only when a virtual server carries both an APM access policy and an OAuth profile, and reporting of F5's advisory puts the exposure on APM acting as an OAuth authorisation server. Systems that use APM only as an OAuth client or resource server are not affected. F5 says no other product is vulnerable, although BIG-IP in Appliance mode is. F5 found the flaw itself and has published indicators of compromise.
The affected releases are BIG-IP 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3. F5 has issued engineering hotfixes for each branch and an iRule, through F5 Support, for customers who cannot patch straight away. CISA's instruction is to apply the iRule first so that forensic checks can take place, then install the final patch as soon as possible.
Who is affected
Any organisation that runs BIG-IP APM with an OAuth authorisation server profile is in scope, whether on hardware, as a virtual edition or through a managed service provider. APM is widely used for single sign-on, remote access and API protection in large companies, universities and the public sector, and because the flaw sits on the traffic-handling side of the device, internet-facing virtual servers matter most.
What to do
- List every virtual server that has both an access policy and an OAuth profile attached. If none does, record that finding and move on.
- For those that do, install the hotfix for your branch. If a change freeze prevents that, deploy F5's iRule now and schedule the hotfix.
- Search logs and systems for F5's published indicators of compromise, before and after patching. An exploited device may already hold stolen tokens or credentials, so treat a hit as an incident rather than a finding.
- If a partner runs your F5 estate, ask for written confirmation of which devices were affected, when the fix went in and whether they checked for compromise.
- Treat 25 September as your own deadline too. The US date binds only federal agencies, but the flaw is already being used against real systems.
Sources
- CISA: CISA Adds Four Known Exploited Vulnerabilities to Catalog — 22 September 2026
- CISA Known Exploited Vulnerabilities catalogue (version 2026.09.23) — 23 September 2026
- F5 security advisory K000162605 (behind a sign-in; date as reported by Rapid7) — 22 September 2026
- Rapid7: CVE-2026-94127, critical unauthenticated RCE in F5 BIG-IP APM — 22 September 2026
- SecurityWeek: Critical F5 BIG-IP vulnerability exploited as zero-day — 23 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.