(TLP:CLEAR) Vulnerability Notification – F5 BIG-IP APM Actively Exploited
Created: Wednesday, September 23, 2026 - 12:04
Categories: Cybersecurity, Security Preparedness
ACTION MAY BE REQUIRED for utilities using F5 BIG-IP Access Policy Manager (APM) configured as an OAuth Authorization Server (an APM access policy and an OAuth authorization server profile configured on a virtual server). Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.
Summary: A critical remote code execution vulnerability affecting F5 BIG-IP Access Policy Manager (APM) is being actively exploited in the wild. Tracked as CVE-2026-94127 (CVSS 9.8), the heap-based buffer overflow vulnerability affects BIG-IP APM deployments configured as an OAuth Authorization Server. Successful exploitation could allow an unauthenticated remote attacker to send specially crafted traffic to an affected virtual server and gain full control of the system. Deployments using APM strictly as an OAuth Client / Resource Server, without OAuth authorization server profiles configured, are not affected.
F5 has confirmed exploitation of the vulnerability, which it discovered internally. On September 22, CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog and directed federal agencies to remediate it within three days.
Analyst Note: This vulnerability is particularly concerning for utilities because BIG-IP APM is a widely deployed network access and identity management solution that controls access to enterprise applications and networks. According to F5, the flaw resides in the data plane rather than the control plane, so restricting access to the BIG-IP management interface does not prevent exploitation. BIG-IP systems running in Appliance mode are also vulnerable. A compromised access gateway could provide attackers with a foothold inside trusted network environments, potentially enabling lateral movement, credential theft, or access to systems that support OT environments.
F5 has released engineering hotfixes for affected versions. No other F5 products, including other BIG-IP modules, BIG-IQ, F5OS, NGINX, and F5 Distributed Cloud services, are affected. F5 evaluates only software versions that have not reached End of Technical Support (EoTS), so utilities running EoTS versions of BIG-IP are encouraged to upgrade to a supported, fixed version.
Affected Versions:
- BIG-IP APM 21.1.0 – install Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, available on F5 Downloads.
- BIG-IP APM 17.5.0 – 17.5.1 – install Hotfix-BIGIP-17.5.1.9.0.160.12-ENG, available on F5 Downloads.
- BIG-IP APM 17.1.0 – 17.1.3 – install Hotfix-BIGIP-17.1.3.5.0.41.14-ENG, available on F5 Downloads.
WaterISAC strongly encourages members to review F5’s advisory, determine whether BIG-IP APM is deployed as an OAuth Authorization Server within their environment, and address the vulnerability according to F5’s recommendations.
Additional Reading
- K000162605: BIG-IP APM vulnerability CVE-2026-94127
- Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Related WaterISAC PIRs: 6, 7, 7.1, 8, 10, 12
