F5 patched a critical zero-day in BIG-IP APM this week. CVE-2026-94127 is a heap-based buffer overflow that allows unauthenticated remote code execution on virtual servers configured with both an APM access policy and an OAuth profile. CVSS score: 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on September 22. Federal agencies have until September 25 to remediate, the shortest remediation window CISA assigns under Binding Operational Directive 22-01.
Active exploitation is confirmed. There is no known workaround for deployments where OAuth is a functional requirement.
What is vulnerable
The flaw lives in the OAuth server code path within BIG-IP APM. When a virtual server is configured to act as an OAuth Authorization Server alongside an APM access policy, a specially crafted network packet triggers a heap-based buffer overflow. The overflow can be weaponized for arbitrary code execution on the BIG-IP management plane.
Affected versions: BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
Not all BIG-IP deployments are affected. The vulnerability requires the co-configuration of an APM access policy and an OAuth profile on the same virtual server. Deployments using BIG-IP purely as a load balancer without APM and OAuth are not in scope.
Attack characteristics
Authentication required: none. User interaction required: none. Attack vector: network. Attack complexity: low. CVSS 3.1 score: 9.8 Critical.
These characteristics mean exploitation is fully automatable and remotely accessible. An attacker with network access to the affected virtual server's port can trigger the overflow without needing any valid credentials or session state.
Why CISA's three-day deadline matters
Under BOD 22-01, CISA typically gives federal agencies two weeks to remediate KEV-listed vulnerabilities. The September 25 deadline is three days from the September 22 KEV addition. CISA reserves this compressed window for BOD 26-04 conditions: confirmed active exploitation, unauthenticated remote access, low attack complexity, and potential total-control impact. All four conditions are met here. The compressed timeline is the clearest signal CISA can send that this requires immediate action.
What to do
First, identify every BIG-IP virtual server in your environment that is configured with both an APM access policy and an OAuth profile. These are the affected configurations.
Second, apply F5's hotfixes immediately. Patches are available for all affected versions. F5's security advisory contains the exact hotfix references.
Third, if patching is not immediately possible for operational reasons, consider temporarily disabling the OAuth profile on affected virtual servers until the patch can be applied. This will break OAuth-dependent workflows but removes the attack surface.
Fourth, review your BIG-IP management access controls. A successful exploit of CVE-2026-94127 gives an attacker code execution on the BIG-IP system itself. If your BIG-IP management interface is accessible from a broad network segment, now is the time to tighten that access as a defense-in-depth measure regardless of patching status.
Remote access infrastructure that also handles authentication is the most attractive target in the enterprise network. A compromised BIG-IP APM system can be used to intercept, modify, or redirect authentication flows for every application behind it. Patch this one now.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you need help prioritizing vulnerability response in your enterprise environment.