F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it.F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild.The flaw can allow an unauthenticated attacker to execute arbitrary code on a vulnerable BIG-IP system. F5 disclosed the issue on September 22 and confirmed that exploitation had already been observed.The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server. More specifically, the vulnerable configuration is one in which APM operates as an OAuth Authorization Server. Systems using APM only as an OAuth Client or Resource Server are not affected.“When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. (CVE-2026-94127)” reads the advisory. “This vulnerability allows an unauthenticated attacker to perform RCE. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. We have learned that this vulnerability has been exploited.”F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0. The company has released hotfixes for the vulnerable branches. The flaw affects the data plane rather than the BIG-IP management plane, and F5 says the appliance mode is also vulnerable.The attack is particularly concerning because BIG-IP appliances are commonly positioned at the edge of corporate networks and handle authentication and access to internal applications. A successful compromise could therefore give an attacker a valuable position from which to move deeper into an organization’s infrastructure.F5 has also provided indicators that defenders can use to look for signs of exploitation. The company recommends paying particular attention to environments showing repeated OAuth authentication failures followed by suspicious commands and, shortly afterward, a TMM SIGABRT event.Organizations that cannot immediately install the hotfix can apply a temporary mitigation. F5 recommends deploying an iRule provided through its support channels to the affected BIG-IP APM virtual server. However, this should be considered a temporary measure rather than a replacement for the security update.Shortly after F5 published its advisory, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog. US federal agencies were instructed to address the vulnerability by September 25, 2026.Internet exposure also appears significant. Shadowserver is currently tracking more than 14,700 IP addresses showing BIG-IP APM fingerprints, although this number does not indicate how many systems are actually vulnerable or unpatched.For organizations running BIG-IP APM, the immediate priority is to determine whether the affected OAuth configuration is in use, identify exposed systems, install the appropriate hotfix and review logs for possible compromise.Because F5 has confirmed active exploitation, administrators should also treat patching as an incident-response priority rather than as routine vulnerability management.F5 advisory and technical details: F5 BIG-IP APM security advisoryFollow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, F5 BIG-IP)