# Critical F5 BIG-IP Vulnerability Under Active Attack: Immediate Action Required

*Published September 25, 2026*
*Source: [https://cybersecuritynews.com/f5-big-ip-oauth-server-0-day-flaw/](https://cybersecuritynews.com/f5-big-ip-oauth-server-0-day-flaw/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/critical-f5-big-ip-vulnerability-under-active-attack-immediate-action-required) or [see plans](https://www.sec-news.ai/pricing).*

## Article

F5 Networks has issued a warning about a critical zero-day vulnerability being actively exploited in their BIG-IP Access Policy Manager (APM) deployments. This vulnerability, identified as CVE-2026-94127, allows attackers to execute code remotely without needing authentication. The flaw specifically affects virtual servers configured with an APM access policy and an OAuth profile, especially when APM acts as an OAuth Authorization Server. F5 released an advisory on September 22, 2026, after confirming that the vulnerability had been weaponized by attackers.

The issue is rooted in a heap-based buffer overflow, categorized under CWE-122, which can lead to arbitrary code execution if exploited. It has been given critical severity scores of 9.8 and 9.3 by CVSS v3.1 and v4.0, respectively. These scores reflect the low complexity required for attacks, network reachability, and the potential severe impact on confidentiality, integrity, and availability. Importantly, vulnerability exposure depends on specific configurations rather than the mere presence of APM. Systems using APM only as an OAuth Client or Resource Server are not affected, but those in appliance mode are still vulnerable.

F5 clarifies that the vulnerability resides in the data plane, affecting application traffic processing, and does not expose the control plane. This means that simply restricting the management interface will not prevent exploitation on vulnerable servers. Affected versions include BIG-IP APM 21.1.0, versions 17.5.0 through 17.5.1, and versions 17.1.0 through 17.1.3. Other F5 products remain unaffected.

F5 has released engineering hotfixes to address the vulnerability, and organizations are urged to apply these immediately. Where patching is not feasible, F5 Support can provide an iRule to mitigate attacks temporarily. Security teams should also search for signs of exploitation, such as repeated OAuth authentication failures and suspicious command executions. The Cybersecurity and Infrastructure Security Agency (CISA) has recognized the urgency by adding this vulnerability to its Known Exploited Vulnerabilities catalog.

F5 discovered the vulnerability internally, and while there is no public information about the identity of the attackers or their objectives, the situation necessitates immediate attention from security teams. Log preservation and analysis of suspicious activities should be prioritized, especially focusing on configurations exposed as OAuth Authorization Servers.
