This is not a theoretical alert to leave in next Monday queue. On 22 September 2026, F5 published advisory K000162605 for CVE-2026-94127, a critical flaw in BIG-IP Access Policy Manager. Hours later, CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue, and reporting from SecurityWeek and BleepingComputer confirmed the essential point: exploitation is already happening in the wild.
The bug enables unauthenticated remote code execution, with a CVSS score of 9.8, when a BIG-IP APM virtual server combines an access policy with an OAuth profile and the system acts as an OAuth Authorization Server. According to the CVE record, it is a heap-based buffer overflow. For administrators, the shorter version matters most: if the right configuration is exposed, malicious traffic can compromise the appliance without credentials.
The scope is specific, but serious enough to demand immediate inventory. Affected versions include BIG-IP APM 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3, when used in that configuration. Deployments using APM only as an OAuth Client or Resource Server are not in the same scenario, and F5 notes that this is a data-plane issue rather than direct control-plane exposure. That distinction helps avoid generic panic, but it does not reduce urgency for teams inside the scope.
What changes for network teams
The difference from many enterprise vulnerabilities is the product position. BIG-IP often sits at the edge of a network, between users, internal applications, VPNs, authentication, and sensitive traffic. An unauthenticated flaw in that kind of component is not just another routine patch; it is a possible entry point for observing, changing, or disrupting critical flows.
The Center for Internet Security describes the risk as exploitation of a public-facing application, aligned with MITRE ATT&CK technique T1190. The practical part is easy to write and hard to execute well: identify every virtual server combining an APM access policy and OAuth Authorization Server, apply the correct hotfix, preserve evidence before disruptive changes, and review logs for correlated signals.
How to read the indicators
F5 and CERT-EU point to a sequence that deserves human review: multiple OAuth failures, suspicious commands, and shortly after that a TMM SIGABRT. The European advisory on the case recommends checking /var/log/apm, /var/log/audit, and OAuth statistics, instead of treating one isolated event as automatic proof of compromise.
That also changes the conversation inside teams. It is not enough to ask whether the patch was installed. Teams need to ask whether a vulnerable configuration existed before the patch, whether anomalous traffic appeared, whether relevant core files exist, whether snapshots and logs were preserved, and whether the F5-provided iRule mitigation was used only as a bridge when immediate updating was not possible.
For now, the closing note is unglamorous and very concrete. If your organisation uses BIG-IP APM, first confirm whether OAuth Authorization Server is present in the affected configuration. If it is, treat CVE-2026-94127 as a potential incident: update, hunt indicators, and document decisions. The news matters today because this is the kind of zero-day that does not need phishing, a stolen password, or a distracted user to begin the story.
Comments (0)
No comments yet.