Critical security vulnerability in F5 BIG-IP Access Policy Manager (CVE-2026-94127)
A critical security vulnerability in F5 BIG-IP Access Policy Manager (APM) is being exploited in the wild, potentially allowing attackers to remotely execute malicious code on vulnerable systems.
Tracked as CVE-2026-94127, the flaw is a heap-based buffer overflow that affects BIG-IP APM when an access policy and an OAuth profile are configured on the same virtual server. Under these conditions, specially crafted network traffic can allow an unauthenticated attacker to execute arbitrary code on the affected device.
The vulnerability carries a CVSS 3.1 score of 9.8 out of 10, putting it in the critical severity category. Under CVSS 4.0, it has a score of 9.3. The vulnerability is identified as CWE-122, a heap-based buffer overflow.
F5 confirmed that CVE-2026-94127 has been exploited in the wild. The US Cybersecurity and Infrastructure Security Agency (CISA) subsequently added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalogue on 22 September 2026.
The affected configurations include BIG-IP versions 17.1.0 through 17.1.3, 17.5.0 through 17.5.1 and version 21.1.0, although the vulnerability only applies when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM solely as an OAuth Client or Resource Server are not affected.
F5 has released fixes for the affected versions. Administrators should apply the appropriate security update, including Hotfix-BIGIP-17.1.3.5.0.41.14-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG or Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, depending on the version deployed.
The NHS England National CSOC has warned that further exploitation is highly likely, noting that internet-facing edge devices such as F5 BIG-IP systems are attractive targets for attackers. Organisations are being advised to review their BIG-IP deployments and prioritise patching vulnerable systems.
CVE-2026-94127 is described as a data-plane vulnerability, meaning there is no control-plane exposure. However, successful exploitation could provide an unauthenticated attacker with remote code execution on the affected BIG-IP system, potentially giving them significant control over the device.
Organisations running F5 BIG-IP APM should check their configurations immediately and apply the relevant F5 security update. Where immediate remediation is not possible, F5 has made an iRule mitigation available through its support process, although installing the vendor-provided fix remains the recommended action.

Blogger at www.systemtek.co.uk
