ON 22 September 2026, F5 disclosed CVE-2026-94127, a critical vulnerability in BIG-IP Access Policy Manager (APM), with a CVSS v3 score of 9.8. F5 said the flaw is being exploited in the wild. It affects BIG-IP versions 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3; other BIG-IP modules and NGINX products are described as unaffected. Appliance-mode systems are also vulnerable.
The issue is a heap-based buffer overflow in the Traffic Management Microkernel’s data plane. Where an APM access policy and OAuth profile are configured on a virtual server, specially crafted network traffic can cause remote code execution without authentication. F5 said this is a data-plane issue, with no control-plane exposure. The article says no public proof-of-concept code has been confirmed.
F5 has issued engineering hotfixes: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG. Administrators are urged to apply the relevant update immediately. If that is not possible, F5 Support can provide an emergency iRule mitigation. The report also recommends reviewing logs for repeated OAuth authentication failures.