Attackers are already exploiting a critical F5 BIG-IP zero-day, with a federal remediation deadline arriving Sept. 25. CVE-2026-94127 can allow an unauthenticated attacker to execute code on vulnerable BIG-IP Access Policy Manager (APM) systems.
F5 disclosed the flaw on Sept. 22 after learning it had been exploited and released engineering hotfixes for affected BIG-IP branches. CISA added it to the Known Exploited Vulnerabilities catalog the same day, giving covered federal civilian agencies with affected, in-scope systems only three days to remediate it.
Only a specific BIG-IP APM configuration is exposed. F5’s security advisory says the flaw is present when APM operates as an OAuth Authorization Server with an APM access policy and OAuth profile configured on the same virtual server. Deployments using APM only as an OAuth client or resource server are not affected.
Why CVE-2026-94127 allows remote code execution
CVE-2026-94127 is a heap-based buffer overflow. According to Rapid7’s technical analysis, specially crafted traffic sent to an affected virtual server can trigger remote code execution without authentication.
F5 rates the vulnerability at 9.8 under CVSS v3.1 and 9.3 under CVSS v4.0. Affected releases include BIG-IP 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3. Releases that have reached End of Technical Support were not evaluated.
The flaw affects the BIG-IP data plane, and systems operating in Appliance mode remain vulnerable. F5 says there is no control-plane exposure.
Patch first, then check for compromise
CISA added CVE-2026-94127 to its KEV catalog on Sept. 22, with a Sept. 25 remediation deadline for covered federal civilian agencies with in-scope assets. CISA’s guidance also encourages other organizations to prioritize KEV-listed flaws through risk-based vulnerability management. CISA has recently placed other actively exploited enterprise flaws on similarly short federal remediation timelines.
Security teams should take these steps:
- Confirm exposure. Check whether BIG-IP APM is acting as an OAuth Authorization Server with both an APM access policy and OAuth profile on the same virtual server.
- Apply the appropriate hotfix. Fixed engineering builds are Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG for the 21.1, 17.5, and 17.1 branches, respectively.
- Use F5’s temporary mitigation if patching must wait. Customers can request an iRule through F5 Support to reduce exposure while preparing for the permanent fix and conducting forensic triage.
- Preserve evidence and hunt for compromise. A CERT-EU advisory advises checking for repeated OAuth authentication failures, suspicious audit-log commands, and subsequent TMM SIGABRT activity. That patch-and-hunt approach also surfaced in recent RouterOS exploitation, where administrators were advised to check whether attackers gained access before fixes were installed.
- Test incident response plans. Confirm that escalation, evidence preservation, system isolation, investigation, and recovery procedures work if defenders uncover signs of compromise.
Recent Cisco FMC intrusions also involved stolen credentials and configurations, plus access paths into internal systems. For CVE-2026-94127, patching closes the known exposure, while forensic review helps establish whether attackers reached the system before remediation.
Also read: A crowded patch queue makes prioritization critical, as Microsoft’s September Patch Tuesday release also showed with two actively exploited Windows zero-days among nearly 1,000 fixes.





