F5 Patches Critical BIG-IP Flaw Already Being Exploited to Hijack Systems Without a Password
F5 has disclosed a critical zero-day vulnerability, tracked as CVE-2026-94127, in its BIG-IP Access Policy Manager (APM) product that is already being exploited by attackers. The flaw affects systems where APM is configured as an OAuth authorization server, issuing access tokens to applications. A specially crafted request sent to the affected virtual server can trigger a heap-based buffer overflow, allowing an attacker to run code on the device without logging in first. F5 has rated the flaw 9.8 out of 10 on the CVSS v3.1 scale, reflecting its severity.
Importantly, restricting access to the BIG-IP management interface will not stop this attack, because the malicious traffic targets the virtual server that handles OAuth traffic directly, not the admin console. Systems running in Appliance mode are also vulnerable. The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on September 22 and ordered federal agencies to apply mitigations within days, underlining the urgency.
F5 has released engineering hotfixes for the affected versions. Organisations using APM only as an OAuth client or resource server (without an authorization server profile) are not affected. Details on how many systems have been compromised or who is behind the attacks have not been disclosed.