F5 has warned customers that attackers are actively exploiting a critical zero-day vulnerability in BIG-IP Access Policy Manager (APM) that can allow unauthenticated remote code execution.

Tracked as CVE-2026-94127, the vulnerability affects specific BIG-IP virtual server configurations where an APM access policy is combined with an OAuth profile and APM is operating as an OAuth Authorization Server.

F5 disclosed the issue in advisory K000162605 on September 22, 2026, after confirming that the vulnerability had already been exploited in the wild.

Critical Heap-Based Buffer Overflow

The flaw is classified as a heap-based buffer overflow (CWE-122) and is tracked internally by F5 as 2524777.

Attackers can send specially crafted network traffic to an affected virtual server, potentially corrupting memory and executing arbitrary code on the BIG-IP system.

The vulnerability carries a CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3. Attackers can exploit it remotely without authentication, user interaction, or existing privileges.

Which BIG-IP Configurations Are Affected?

The vulnerability does not affect every BIG-IP deployment running APM.

According to F5, exposure depends on the specific configuration. Systems using APM only as an OAuth Client or Resource Server are not affected when an OAuth Authorization Server profile is not configured.

However, appliance-mode systems remain vulnerable.

F5 also said the issue exists in the data plane, which handles application traffic. Because the control plane is not involved, simply restricting access to the BIG-IP management interface does not prevent attacks against an exposed vulnerable virtual server.

Affected releases include:

  • BIG-IP APM 21.1.0

  • BIG-IP 17.5.0 through 17.5.1

  • BIG-IP 17.1.0 through 17.1.3

F5 has stated that other products and services, including BIG-IQ Centralized Management, BIG-IP Next, F5 Distributed Cloud services, NGINX products, F5OS variants, and F5 AI Gateway, are not affected.

However, releases that are already beyond their End of Technical Support period were not evaluated.

F5 Releases Emergency Hotfixes

F5 has made engineering hotfixes available for the affected branches:

  • Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso

  • Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso

  • Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso

Organizations should identify BIG-IP APM virtual servers using the affected OAuth Authorization Server configuration and apply the appropriate hotfix as soon as p