<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/f5-fixes-actively-exploited-zero-day-flaw-in-big-ip-apm-yrwq0fql8" -->

---
title: F5 fixes actively exploited zero-day flaw in BIG-IP APM
description: F5 patched a critical zero-day remote code execution vulnerability (CVE-2026-94127, CVSS 9.8) in BIG-IP Access Policy Manager affecting deployments configured...
canonical: https://daily.dev/posts/f5-fixes-actively-exploited-zero-day-flaw-in-big-ip-apm-yrwq0fql8
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: F5 fixes actively exploited zero-day flaw in BIG-IP APM | daily.dev
og:description: F5 patched a critical zero-day remote code execution vulnerability (CVE-2026-94127, CVSS 9.8) in BIG-IP Access Policy Manager affecting deployments configured...
og:url: https://daily.dev/posts/f5-fixes-actively-exploited-zero-day-flaw-in-big-ip-apm-yrwq0fql8
og:image: https://api.daily.dev/og/posts/yrWQ0fql8.png
og:image:alt: F5 fixes actively exploited zero-day flaw in BIG-IP APM
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# F5 fixes actively exploited zero-day flaw in BIG-IP APM

**[CSO Online](https://daily.dev/sources/csoonline)** · 3 min read · 0 upvotes · 0 comments

## Summary

F5 patched a critical zero-day remote code execution vulnerability (CVE-2026-94127, CVSS 9.8) in BIG-IP Access Policy Manager affecting deployments configured with an OAuth authorization server profile. The heap-based buffer overflow was already being actively exploited before the fix shipped and has been added to CISA's Known Exploited Vulnerabilities catalog. Shadowserver estimates over 15,000 internet-exposed BIG-IP APM deployments, with North America and Europe each accounting for roughly 5,000. F5 published hotfixes for the 21.x, 17.5.x, and 17.1.x branches plus a mitigating iRule, and detailed indicators of compromise including repeated OAuth authentication failures, suspicious commands, and TMM SIGABRT crashes that admins should correlate to detect exploitation.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4225721/f5-fixes-actively-exploited-zero-day-flaw-in-big-ip-apm.html>

## Questions this post answers

### What is CVE-2026-94127 and how severe is it?

CVE-2026-94127 is a heap-based buffer overflow in F5 BIG-IP Access Policy Manager (APM) rated 9.8 on the CVSS scale, allowing remote code execution. It affects deployments configured as OAuth authorization servers, including systems in appliance mode, and was under active exploitation before F5 released a patch. It was added to CISA's Known Exploited Vulnerabilities catalog.

_Teams running F5 BIG-IP can track critical CVEs like this one on daily.dev to react before exploitation spreads._

### How do I fix CVE-2026-94127 on F5 BIG-IP APM?

Apply the hotfix matching your branch: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso for 21.x, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso for 17.5.x, or Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso for 17.1.x. F5 also released an iRule from the support portal as a temporary mitigation for systems that cannot be patched immediately. Only APM deployments with an OAuth authorization server profile configured are affected.

_Admins patching BIG-IP APM can follow security advisories like this one on daily.dev to stay ahead of exploited flaws._

### How can I detect if my F5 BIG-IP APM was exploited via CVE-2026-94127?

Correlate multiple indicators rather than relying on one signal: more than 10 OAuth authentication failures from the same IP, followed by suspicious commands, followed by a TMM SIGABRT crash. Run tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed to check failure counts, then review /var/log/audit around suspicious timestamps and check for TMM core files indicating a crash loop.

_Security teams monitoring edge devices can follow incident indicators like these on daily.dev to catch exploitation early._

## Similar posts on daily.dev

- [Stealth rootkit targeting F5 BIG-IP could expose enterprise identity gateways](https://daily.dev/posts/stealth-rootkit-targeting-f5-big-ip-could-expose-enterprise-identity-gateways-k4zt4gkhl) · CSO Online · 0 upvotes · 0 comments
- [Fortinet BIG-IP Vuln Reclassified as RCE, Under Exploitation](https://daily.dev/posts/fortinet-big-ip-vuln-reclassified-as-rce-under-exploitation-3gdeh2jrm) · Dark Reading · 1 upvotes · 1 comments
- [F5 issues out-of-band patches for critical NGINX vulnerabilities](https://daily.dev/posts/f5-issues-out-of-band-patches-for-critical-nginx-vulnerabilities-fsoycazfr) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#oauth](https://daily.dev/tags/oauth)

[View this post on daily.dev](https://daily.dev/posts/f5-fixes-actively-exploited-zero-day-flaw-in-big-ip-apm-yrwq0fql8)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"F5 fixes actively exploited zero-day flaw in BIG-IP APM","url":"https://daily.dev/posts/f5-fixes-actively-exploited-zero-day-flaw-in-big-ip-apm-yrwq0fql8","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/f5-fixes-actively-exploited-zero-day-flaw-in-big-ip-apm-yrwq0fql8"},"datePublished":"2026-09-23T20:46:06.931Z","dateModified":"2026-09-23T23:24:01.709Z","description":"F5 patched a critical zero-day remote code execution vulnerability (CVE-2026-94127, CVSS 9.8) in BIG-IP Access Policy Manager affecting deployments configured...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a8004509e0310fd9b973484e59964ad6?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a8004509e0310fd9b973484e59964ad6?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/f5-fixes-actively-exploited-zero-day-flaw-in-big-ip-apm-yrwq0fql8","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,oauth","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"F5 fixes actively exploited zero-day flaw in BIG-IP APM"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/f5-fixes-actively-exploited-zero-day-flaw-in-big-ip-apm-yrwq0fql8#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2026-94127 and how severe is it?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-94127 is a heap-based buffer overflow in F5 BIG-IP Access Policy Manager (APM) rated 9.8 on the CVSS scale, allowing remote code execution. It affects deployments configured as OAuth authorization servers, including systems in appliance mode, and was under active exploitation before F5 released a patch. It was added to CISA's Known Exploited Vulnerabilities catalog. Teams running F5 BIG-IP can track critical CVEs like this one on daily.dev to react before exploitation spreads."}},{"@type":"Question","name":"How do I fix CVE-2026-94127 on F5 BIG-IP APM?","acceptedAnswer":{"@type":"Answer","text":"Apply the hotfix matching your branch: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso for 21.x, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso for 17.5.x, or Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso for 17.1.x. F5 also released an iRule from the support portal as a temporary mitigation for systems that cannot be patched immediately. Only APM deployments with an OAuth authorization server profile configured are affected. Admins patching BIG-IP APM can follow security advisories like this one on daily.dev to stay ahead of exploited flaws."}},{"@type":"Question","name":"How can I detect if my F5 BIG-IP APM was exploited via CVE-2026-94127?","acceptedAnswer":{"@type":"Answer","text":"Correlate multiple indicators rather than relying on one signal: more than 10 OAuth authentication failures from the same IP, followed by suspicious commands, followed by a TMM SIGABRT crash. Run tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed to check failure counts, then review /var/log/audit around suspicious timestamps and check for TMM core files indicating a crash loop. Security teams monitoring edge devices can follow incident indicators like these on daily.dev to catch exploitation early."}}]}
```

