F5 has confirmed that attackers are actively exploiting a critical flaw in BIG-IP Access Policy Manager (APM), a component many organisations use to control who and what can reach their applications. The bug, tracked as CVE-2026-94127 (CVSS 9.8), lets an attacker run code on the device with no login required — but only on systems where APM has been set up as an OAuth Authorization Server, with an APM access policy and an OAuth profile configured on the same virtual server. BIG-IP deployments using APM purely as an OAuth client, or not using OAuth at all, are not affected by this specific flaw.
F5 has released hotfixes across its supported branches and says it has evidence of real-world exploitation, though it hasn't disclosed how many organisations have been hit. Security researchers at Shadowserver count more than 14,700 internet-facing BIG-IP APM systems that could potentially be affected, though not all of them run the vulnerable OAuth configuration. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 22 September and has given US federal agencies until this Friday, 25 September, to apply the fix — a tight window that reflects how seriously the agency is treating active exploitation of internet-facing access-management infrastructure.
What this means for your business
If your organisation runs F5 BIG-IP — commonly deployed at the network edge to manage remote access, VPN-style connections, or single sign-on to internal apps — ask whoever manages that infrastructure two things this week: first, whether APM is configured as an OAuth Authorization Server (the specific setup this flaw needs), and second, whether the hotfix for CVE-2026-94127 has been applied. This is exactly the kind of infrastructure that sits between the internet and your internal systems, so a flaw here is worth treating with urgency even without a federal deadline attached to it. If you don't manage this equipment directly, this is a good prompt to check with your IT provider or managed-services vendor that BIG-IP devices on your network have been reviewed against F5's advisory.