To hack the corporate gateway F5 may now not need a password or an account. The company has uncovered a critical vulnerability in the BIG-IP Access Policy Manager that attackers are already using in real-world attacks. A similar scenario with an actively exploited gap in the F5 BIG-IP was observed just a few months ago.
The new problem received the CVE-2026-94127 ID and a score of 9.8 points out of 10 on CVSS 3.1. The reason lies in the buffer overflow in dynamic memory. Specially generated network traffic allows a remote attacker to execute arbitrary code without authentication. The vulnerable component is related to OAuth, which is widely used for authorization between applications and services.
Not all BIG-IP installations are hit. To attack, the virtual server must simultaneously use the APM access policy and the OAuth profile, with APM having to work as an OAuth Authorization Server. Systems where the module is only used as an OAuth Client or Resource Server are not exposed to vulnerabilities. Appliance Mode does not protect against the problem.
F5 confirmed the problem in BIG-IP APM 17.1.0–17.1.3, 17.5.0–17.5.1 and 21.1.0. The versions, which have expired the term of technical support, the company did not check. Other BIG-IP, BIG-IQ Centralized Management, BIG-IP Next, F5OS, F5 Distributed Cloud and NGINX modules are not used by CVE-2026-94127. In June, F5 was already releasing unscheduled fixes for several of its ecosystem products.
CISA entered CVE-2026-94127 in the KEV catalog on September 22, the day of public disclosure. U.S. federal civil affairs are mandated to address the vulnerability by September 25, 2026. Such a short period of time is associated with confirmed exploitation. Details of the attackers, the scale of the campaign and the hacking chain used have not yet been disclosed.
Administrators are advised to look for a combination of several signs. Among them are at least ten repetitive OAuth authentication errors in a short time, especially from one IP address, suspicious commands in the /var/log/audit log, and the subsequent SIGABRT alarm of the TMM process. A single mistake alone does not yet confirm the hack. The F5 already had similar experiences when the critical BIG-IP breach began to be used in real-world attacks shortly after disclosure.
For vulnerable branches, separate fixes have been issued: Hotfix-BIGIP-17.1.3.5.41.14-ENG, Hotfix-BIGIP-17.5.1.9.1.0.10.12-ENG and Hotfix-BIGIP-21.1.0.2.0.30.22-ENG. If it is not possible to fix a fix quickly, F5 offers temporary protection based on iRule, which can be obtained through support. The company advises first to save the data for investigation, then update the system and check the logs for signs of already occurring penetration.
The context makes the new 0day particularly unpleasant. In the fall of 2025, F5 itself experienced a large-scale compromise in which attackers gained access to the BIG-IP source code and materials about undisclosed vulnerabilities. Then on the Internet there were about 269 thousand available from outside BIG-IP devices.
The history of BIG-IP has repeatedly shown how quickly critical errors turn into a working tool of the attackers. In May 2022, public exploits appeared for another vulnerability with a 9.8 score, after which mass exploitation of vulnerable systems began. CVE-2026-94127 differs in that the real attacks were confirmed by the time of public disclosure.
The new problem received the CVE-2026-94127 ID and a score of 9.8 points out of 10 on CVSS 3.1. The reason lies in the buffer overflow in dynamic memory. Specially generated network traffic allows a remote attacker to execute arbitrary code without authentication. The vulnerable component is related to OAuth, which is widely used for authorization between applications and services.
Not all BIG-IP installations are hit. To attack, the virtual server must simultaneously use the APM access policy and the OAuth profile, with APM having to work as an OAuth Authorization Server. Systems where the module is only used as an OAuth Client or Resource Server are not exposed to vulnerabilities. Appliance Mode does not protect against the problem.
F5 confirmed the problem in BIG-IP APM 17.1.0–17.1.3, 17.5.0–17.5.1 and 21.1.0. The versions, which have expired the term of technical support, the company did not check. Other BIG-IP, BIG-IQ Centralized Management, BIG-IP Next, F5OS, F5 Distributed Cloud and NGINX modules are not used by CVE-2026-94127. In June, F5 was already releasing unscheduled fixes for several of its ecosystem products.
CISA entered CVE-2026-94127 in the KEV catalog on September 22, the day of public disclosure. U.S. federal civil affairs are mandated to address the vulnerability by September 25, 2026. Such a short period of time is associated with confirmed exploitation. Details of the attackers, the scale of the campaign and the hacking chain used have not yet been disclosed.
Administrators are advised to look for a combination of several signs. Among them are at least ten repetitive OAuth authentication errors in a short time, especially from one IP address, suspicious commands in the /var/log/audit log, and the subsequent SIGABRT alarm of the TMM process. A single mistake alone does not yet confirm the hack. The F5 already had similar experiences when the critical BIG-IP breach began to be used in real-world attacks shortly after disclosure.
For vulnerable branches, separate fixes have been issued: Hotfix-BIGIP-17.1.3.5.41.14-ENG, Hotfix-BIGIP-17.5.1.9.1.0.10.12-ENG and Hotfix-BIGIP-21.1.0.2.0.30.22-ENG. If it is not possible to fix a fix quickly, F5 offers temporary protection based on iRule, which can be obtained through support. The company advises first to save the data for investigation, then update the system and check the logs for signs of already occurring penetration.
The context makes the new 0day particularly unpleasant. In the fall of 2025, F5 itself experienced a large-scale compromise in which attackers gained access to the BIG-IP source code and materials about undisclosed vulnerabilities. Then on the Internet there were about 269 thousand available from outside BIG-IP devices.
The history of BIG-IP has repeatedly shown how quickly critical errors turn into a working tool of the attackers. In May 2022, public exploits appeared for another vulnerability with a 9.8 score, after which mass exploitation of vulnerable systems began. CVE-2026-94127 differs in that the real attacks were confirmed by the time of public disclosure.