Active zero-day targets F5 BIG-IP APM (CVE-2026-94127)
F5 and CISA warn attackers are exploiting CVE-2026-94127 in BIG-IP APM for unauthenticated remote code execution; F5 issued hotfixes and indicators of compromise.
F5 and the Cybersecurity and Infrastructure Security Agency issued a joint advisory Tuesday that threat actors are actively exploiting a critical zero-day in BIG-IP Access Policy Manager, tracked as CVE-2026-94127. F5 published hotfixes for affected releases and provided three indicators of compromise to assist detection and response.
The vulnerability has a CVSS score of 9.8 and can be triggered when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server with APM acting as an OAuth Authorization Server. Deployments using APM as an OAuth Client or Resource Server are not affected.
F5 identified the defect internally and observed exploitation in the wild. The company noted the error affects BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3, and that BIG-IP systems running in Appliance mode are vulnerable. F5 described the issue as a data plane problem with no control plane exposure and wrote, “We have learned that this vulnerability has been exploited.”
The exploit is delivered via specially crafted traffic sent to a vulnerable virtual server when the specified APM and OAuth settings are in place. Successful exploitation allows an unauthenticated attacker to execute arbitrary code on the appliance, which can lead to full system compromise and control over traffic processed by the device.
Shortly after F5 released its advisory, CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities list and instructed federal agencies to apply patches within three days under Binding Operational Directive 26-04. The KEV listing requires rapid remediation for government networks.
F5 supplied three indicators of compromise and advised that their combined and frequent appearance should be correlated during investigations. The vendor released hotfixes for the identified releases and recommended that organizations prioritize systems running the affected versions and monitor for the published IoCs.
BIG-IP APM is used by enterprises to manage remote access and enforce application access policies. F5 urged administrators to review APM OAuth configurations and inventory deployed versions to determine exposure.
The advisory from F5 and the CISA directive set timelines and detection details for organizations with affected systems to apply hotfixes and to use the provided IoCs when searching for potential compromises.







