F5 has issued fixes for a critical BIG-IP Access Policy Manager vulnerability that the company says has already been exploited in the wild.
CVE-2026-94127 does not affect every BIG-IP APM installation, but it is serious for organizations using the affected configuration. Advisories and reporting available on September 25, 2026, indicate the vulnerable setup involves BIG-IP APM acting as an OAuth Authorization Server, with both an APM access policy and an OAuth profile on the same virtual server.
Deployments using APM strictly as an OAuth Client or OAuth Resource Server, without OAuth authorization server profiles configured, were reported by F5 as not affected. Software versions that have reached End of Technical Support were not evaluated by F5, so old branches should not be treated as cleared by omission.
Affected versions and hotfixes
| BIG-IP APM branch | Affected versions | Fixed hotfix |
|---|---|---|
| 21.1 | 21.1.0 before the engineering hotfix | Hotfix-BIGIP-21.1.0.2.0.30.22-ENG |
| 17.5 | 17.5.0 through 17.5.1 before the engineering hotfix | Hotfix-BIGIP-17.5.1.9.0.160.12-ENG |
| 17.1 | 17.1.0 through 17.1.3 before the engineering hotfix | Hotfix-BIGIP-17.1.3.5.0.41.14-ENG |
The hotfix names should be checked against the current F5 advisory before production changes, since vendor engineering hotfix guidance can change.
Why the risk is high
CVE-2026-94127 is a remote code execution issue that does not require authentication. Rapid7 said exploitation requires network access to an affected virtual server rather than access to the BIG-IP management plane.
That detail affects remediation planning. Management interface restrictions remain good security hygiene, but they are not a fix for this vulnerability because the malicious traffic reaches the virtual server itself. Rapid7 and SecurityWeek also reported that BIG-IP systems in Appliance mode remain vulnerable because the issue is on the data plane, not the control plane.
The U.S. Cybersecurity and Infrastructure Security Agency also added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog on September 22, according to Rapid7, BleepingComputer, and SecurityWeek. BleepingComputer reported that federal civilian agencies were directed to secure affected systems by September 25.
Recommended response
The Canadian Cyber Centre recommends identifying BIG-IP systems where an APM access policy and OAuth profile are configured on the same virtual server, applying the relevant vendor-supported hotfix, and using F5’s vendor-provided iRule through F5 Support if an immediate hotfix is not possible.
CERT-EU’s recommended order of operations is to preserve forensic evidence, apply the hotfix, check for signs of compromise, and start incident response if signs are found. That sequence matters because a patched system may still need investigation if it was exposed before the fix.
Compromise checks to prioritize
CERT-EU said administrators should treat a cluster of signals as suspicious when repeated OAuth authentication failures are followed by suspicious commands and a TMM SIGABRT shortly after.
- APM logs: Review
/var/log/apmfor repeated failed UserInfo requests, especially 10 or more from a single IP address in a short window. - OAuth statistics: Check for unexplained growth in
total_failedusingtmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed. - Audit logs: Review
/var/log/auditaround the same timestamps for suspicious commands. - TMM core files: Investigate core files in context. CERT-EU said a TMM core file alone is not an indicator, but it should be reviewed when paired with other signals.
Public reporting as of September 25, 2026, had not identified the attackers, target organizations, or a confirmed public proof-of-concept exploit. That uncertainty should keep response plans cautious rather than delayed.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us







