SOCLYDE logo
Current languageEN
Cybersecurity newsVulnerabilityF5Remote access

F5 big-ip apm: a flaw allowing code execution is being exploited

CVE-2026-94127 affects specific BIG-IP APM OAuth configurations and is under active exploitation. Here are the priority checks.

By Soclyde Team

A technician works on a network cabinet in a corridor

In summary

  • CVE-2026-94127 is a critical heap-based overflow in BIG-IP Access Policy Manager.
  • The documented risk targets virtual servers configured with an access policy and an OAuth authorization-server profile.
  • F5 and multiple public-sector advisories recommend patching and checking for compromise.

Explore next

Soclyde resources

Article contents

On September 22, 2026, F5 published an advisory for CVE-2026-94127, a critical BIG-IP Access Policy Manager vulnerability exploited in the wild. The issue does not indiscriminately affect every appliance: it targets a specific configuration involving an access policy and an OAuth profile used as an authorization server.

The affected configuration scenario

CVE-2026-94127 is a heap-based overflow that can lead to unauthenticated remote code execution under the configuration described by F5. The access layer then becomes a privileged entry point because it processes sign-in requests and policies protecting internal applications.

Compare deployed versions and profiles with F5’s advisory. An APM deployment used only as an OAuth client or resource server is not described the same way in the sources. That distinction avoids both a blanket false alarm and a missed exposed virtual server.

Why exploitation changes the priority

F5 and advisories from CERT-EU, Canada’s Cyber Centre and JPCERT/CC report active risk. They recommend rapid action, but they do not publish a complete victim list or proof that every vulnerable system was compromised.

A compromised BIG-IP APM could nevertheless expose sessions, federation configuration and paths into protected applications. Patching alone is therefore not enough when the interface was reachable from uncontrolled networks.

Priority actions for network teams

Inventory BIG-IP versions and virtual servers combining APM, an access policy and an OAuth authorization-server profile. Apply the hotfix or fixed release specified by F5. Until then, restrict administration and reduce public exposure where the architecture allows it.

Preserve logs before cleanup. Look for unusual requests, unexpected processes, configuration changes, outbound connections and sessions created outside normal hours. Treat any suspicion with the incident-response team.

Secrets and sessions to review

After potential access, revoke active sessions and rotate service accounts, certificates, keys and passwords used by APM or protected applications. Coordinate rotation with the investigation: it limits reuse of a secret but does not remove persistence already installed.

Users should be cautious with messages requesting a new sign-in after an outage or patch. Phishing campaigns can use a remote-access incident to capture a password or another authentication code.

The Soclyde connection

Soclyde does not patch BIG-IP APM or revoke sessions for the network team. It can support a controlled rotation by generating unique secrets and keeping them in local-first encrypted vaults instead of configuration spreadsheets copied between suppliers.

That organisation complements the hotfix, network restriction and investigation. It is neither protection for the appliance nor proof that access was not compromised.

Key takeaways

CVE-2026-94127 affects specific BIG-IP APM OAuth configurations and is actively exploited. Confirm the exact scope, apply F5’s fix, look for access traces and rotate affected secrets. To structure the rotation, read the secure password generator guide or contact Soclyde.

Frequently asked questions

Are all BIG-IP appliances affected?

No. The documented scope depends on the APM configuration and the OAuth authorization-server role. Check F5’s advisory and exact versions instead of generalising to every BIG-IP deployment.

What should we do before the hotfix can be applied?

Reduce exposure, restrict administration and preserve logs. These steps do not replace the hotfix and should be validated with the network team.

Why rotate secrets after patching?

Code execution on an access device can expose sessions, accounts or configurations. Rotation shortens the life of a potentially read secret, but does not remove the need for forensic review.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading