F5 shipped emergency hotfixes on September 22, 2026, for a critical zero-day in BIG-IP Access Policy Manager after confirming attackers were already exploiting it. The flaw, tracked as CVE-2026-94127, scores 9.8 out of 10 on the CVSS 3.1 scale and lets an unauthenticated attacker run arbitrary code on affected appliances. Hours after F5’s advisory went out, the Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalog and gave federal civilian agencies until September 25 to patch or pull the device offline.

The timing matters. CISA did not add CVE-2026-94127 alone. The same September 22 KEV update included two Check Point flaws and one Arista VeloCloud Orchestrator bug, all four rated as unauthenticated and remotely reachable. That clustering points to a rougher pattern: edge devices, the boxes that sit between the open internet and the corporate network, are absorbing a steady run of critical, actively exploited bugs in 2026, and BIG-IP APM is the latest to join the list.

What F5 Disclosed on September 22

F5’s advisory, published as K000162605, describes a heap-based buffer overflow (CWE-122) in BIG-IP Access Policy Manager. The bug only triggers on virtual servers that combine an APM access policy with an OAuth profile, and only when APM is configured to act as an OAuth Authorization Server. Deployments using APM purely as an OAuth Client or Resource Server are not affected, according to F5’s own scoping notes.

F5’s language in the advisory leaves little room for interpretation: “We have learned that this vulnerability has been exploited,” the company wrote, a rare admission that puts the bug in the same category as a handful of other 2026 edge-device incidents where the vendor confirmed live attacks before most customers had even read the patch notes. F5 also said the flaw sits entirely on the data plane, inside the Traffic Management Microkernel that processes live traffic, with no control-plane exposure. That distinction matters for triage, because locking down the management interface alone will not close this hole.

How the OAuth Heap Overflow Works

An attacker who can reach a vulnerable virtual server sends specially crafted traffic that overflows a heap buffer inside the TMM process handling OAuth authorization requests. No credentials, cookies, or prior access are required. Successful exploitation hands the attacker code execution on the BIG-IP system itself, not just on a backend application behind it. Because BIG-IP APM frequently terminates VPN and single sign-on traffic for an entire organization, a compromised appliance can become a pivot point for credential theft and lateral movement rather than a one-off outage.

CISA rates the CVSS 4.0 score slightly lower, at 9.3, but both scores land in the critical band. The agency added the entry to KEV citing “evidence of active exploitation,” the same phrasing it used for the three other bugs disclosed that day. Researchers tracking the flaw have not confirmed a public proof-of-concept exploit is circulating, which narrows the immediate blast radius to attackers who developed their own tooling rather than opportunistic scanning by low-skill actors. That gap will likely close within days, as it typically has for prior BIG-IP zero-days.

Which BIG-IP Versions Are Exposed

F5 lists three branches as affected: 21.1.0, the 17.5.0 through 17.5.1 range, and 17.1.0 through 17.1.3. Each branch gets its own engineering hotfix rather than a single unified patch, which means administrators running mixed-version fleets need to track three separate downloads. F5 explicitly notes that versions which have already reached End of Technical Support are not evaluated for this CVE at all, so organizations still running unsupported BIG-IP builds get no answer from F5 either way. That silence should be read as a risk signal, not a clean bill of health.

BIG-IP BranchAffected VersionsHotfix ReleasedVulnerable Configuration
21.x21.1.0Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.isoAPM access policy + OAuth profile, OAuth Authorization Server role
17.5.x17.5.0 – 17.5.1Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.isoSame as above, including Appliance mode
17.1.x17.1.0 – 17.1.3Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.isoSame as above, including Appliance mode

Until the hotfix is installed, F5 points administrators toward an interim iRule mitigation that can be applied to the exposed virtual server. CISA’s KEV entry goes further than usual on this point, instructing agencies to apply the iRule first, run forensic triage, and only then move to the final patch, a sequencing choice that assumes some environments were already compromised before the advisory landed.

CISA’s Three-Day Clock and BOD 26-04

CVE-2026-94127 now falls under Binding Operational Directive 26-04, the directive CISA uses to prioritize KEV-listed bugs on internet-facing federal systems. The directive tells agencies to fix vulnerabilities first where exploitation could grant total control of the asset, and CVE-2026-94127 fits that description directly: unauthenticated, remotely reachable, and ending in full code execution. Every KEV entry added that day carries a new field, “Forensic triage required,” which pushes agencies past simple patching and into checking whether an intrusion already happened. A patch closes the door going forward. It does not tell an admin whether someone already walked through it.

The September 25 deadline binds only Federal Civilian Executive Branch agencies, but CISA’s own guidance treats KEV entries as a floor for private-sector risk management too. Security teams outside government rarely get a formal deadline, so the KEV listing functions as the closest thing to one: a signal that the vulnerability has moved from theoretical to weaponized, and that the response window has shrunk from weeks to days. Enterprises running exposed BIG-IP APM instances should treat that same three-day window as the working target, even without a legal requirement to hit it.

Not Alone: Three Other Edge Devices Hit the Same Day

CISA’s September 22 batch grouped the F5 flaw with two Check Point vulnerabilities and one from Arista. CVE-2026-85102 is an improper certificate validation bug in Check Point Security Gateway and Spark Firewall, exploitable over site-to-site or remote-access VPN connections and also capable of unauthenticated code execution. CVE-2026-93616 hits the management layer instead: Check Point Security Management Server and related products carry a path-traversal flaw that lets an attacker upload and run arbitrary scripts, a dangerous outcome since that server stores security policy and processes administrator changes across an entire firewall estate. CVE-2026-93952 affects Arista VeloCloud Orchestrator, the console that manages SD-WAN edge devices, where an input-validation flaw can expose privileged internal functions on the host.

CVEVendor / ProductCWEImpactKEV Due Date
CVE-2026-94127F5 BIG-IP APMCWE-122 (Heap Overflow)Unauthenticated remote code execution2026-09-25
CVE-2026-85102Check Point Security Gateway / SparkCWE-295 (Cert Validation)Unauthenticated RCE on the gateway2026-09-25
CVE-2026-93616Check Point Security Management ServerCWE-22 (Path Traversal)Unauthenticated script upload and execution2026-09-25
CVE-2026-93952Arista VeloCloud OrchestratorCWE-20 (Input Validation)Access to privileged internal functions2026-09-25

None of the four entries currently show confirmed ransomware use, which CISA marks as “Unknown” rather than “No” for all four, leaving the door open as investigations continue. What connects them is more structural than coincidental: every one of the four is a device that sits at the network perimeter or manages the systems that do, and every one is reachable without a login.

Why Edge Appliances Keep Becoming the Entry Point

BIG-IP APM’s role makes it a high-value target well beyond this single bug. It terminates VPN sessions, enforces single sign-on, and often sits directly in front of internal applications that have no independent authentication layer of their own. Compromise one appliance and an attacker can inherit the trust that dozens of backend systems already extend to it. That is a different risk profile than a bug in, say, a single web application, where the blast radius usually stops at that app.

Edge devices from SonicWall, VMware, and remote-management tools have all landed on CISA’s KEV catalog with similarly tight deadlines earlier in 2026, and the pattern keeps repeating: a CVSS score near the ceiling, unauthenticated access, and a patch window measured in days rather than the weeks security teams get for most internal software. VMware’s vCenter RCE, disclosed with a CVSS 9.8 score and confirmed ransomware activity, followed the same script months earlier in the year. So did the N-central remote monitoring flaw, which needed a fourth hotfix in five weeks before F5’s own bug even surfaced.

Historical Context: F5’s Recent Record

F5 has not had a quiet run in 2026. The vendor has issued multiple critical advisories across its BIG-IP product family this year, and CVE-2026-94127 lands in a broader industry stretch where Microsoft’s own September Patch Tuesday shipped fixes for 974 bugs including two zero-days already under attack. The cadence across the industry has shifted. Fewer bugs sit quietly for months before exploitation begins, and more of them get weaponized within days of, or even before, the public advisory. Security teams that once treated a CVSS 9.8 rating as a signal to patch within a sprint cycle are increasingly treating it as a same-week, sometimes same-day, obligation.

The Canadian Centre for Cyber Security also issued its own advisory, AV26-949, flagging active exploitation of CVE-2026-94127, adding a second national cybersecurity authority to the list of agencies treating the bug as an immediate operational risk rather than a routine patch-cycle item.

What Defenders Should Check First

The first step for any BIG-IP administrator is an inventory question, not a patch question: which virtual servers combine an APM access policy with an OAuth profile, and which of those are configured as an OAuth Authorization Server. That narrow condition is the entire attack surface for this bug, so a fleet-wide scan for that specific configuration will separate exposed systems from unaffected ones faster than a blanket patch-everything approach.

  • Identify every virtual server pairing an APM access policy with an OAuth profile
  • Apply F5’s interim iRule mitigation on exposed servers if the hotfix cannot go in immediately
  • Install the branch-specific hotfix (21.1.0, 17.5.x, or 17.1.x) as soon as it is validated in a test environment
  • Review TMM logs for repeated OAuth failures or unexpected process crashes (SIGABRT events)
  • Treat any single indicator as inconclusive and correlate across logs before ruling exploitation in or out
  • Confirm whether any BIG-IP systems in the fleet have already reached End of Technical Support, since F5 does not evaluate those for this CVE

F5’s guidance frames forensic triage as necessary even after the hotfix goes in, since a patch only closes the vulnerable code path going forward. It does nothing to reveal whether an attacker already used the window between the bug’s introduction and its public disclosure.

Market and Enterprise Impact

BIG-IP APM sits deep inside enterprise identity infrastructure at banks, healthcare systems, and government agencies that rely on F5’s platform for VPN and SSO enforcement. A critical, unauthenticated RCE in that layer forces an emergency change-control cycle that most IT teams did not budget for this quarter. Security vendors that sell exposure-scanning and attack-surface-management tools are likely to see a short-term spike in interest, a pattern that followed the JetBrains Cadence breach earlier this year when a CVSS 9.8 bug sat unpatched in production for 16 days before remediation closed the gap.

The broader lesson for enterprise buyers is less about F5 specifically and more about concentration risk. Organizations that route VPN, SSO, and application delivery through a single vendor’s appliance get real operational simplicity in exchange for a single point of catastrophic failure when that vendor discloses a critical, actively exploited bug. F5 is far from alone in that trade-off. The same dynamic played out with the GKE Fragnesia container escape bug for cloud-native teams and with Zyxel’s device fleet compromise for smaller network operators, both disclosed in 2026 and both tied to infrastructure that sits underneath, not inside, the applications security teams usually watch most closely.

Competitive Comparison: Edge and VPN Vendors in 2026

F5’s disclosure lands in a year where nearly every major edge and remote-access vendor has shipped at least one critical, actively exploited advisory. SonicWall’s SMA1000 series carried a CVSS 10 zero-day with a three-day patch deadline. VMware’s vCenter RCE, also rated 9.8, was tied to confirmed ransomware deployment rather than just a proof-of-concept risk. N-able’s N-central remote monitoring platform needed four separate hotfixes across five weeks to fully close its CVSS 10 flaw. Check Point and Arista now join that list from the same September 22 KEV batch as F5.

What differentiates F5’s case is the narrowness of the vulnerable configuration. Unlike a bug that affects every instance of a product by default, CVE-2026-94127 only triggers on virtual servers running APM as an OAuth Authorization Server, a configuration common in enterprises using BIG-IP for federated identity but absent in simpler VPN-only deployments. That narrower blast radius does not make the bug less severe for the organizations that do run it. It does mean patch prioritization can be more targeted than a blanket, fleet-wide emergency change.

Predictions: Where This Goes Next

A handful of trends look likely to play out over the coming weeks and months, based on how similar edge-device disclosures have unfolded earlier in 2026.

  • Expect a public proof-of-concept exploit for CVE-2026-94127 within two to four weeks, following the pattern set by prior BIG-IP zero-days once patches reveal the vulnerable code path to researchers.
  • Ransomware operators will likely probe unpatched BIG-IP APM instances once tooling becomes available, given how quickly criminal groups adopted the VMware vCenter bug earlier this year.
  • More national cybersecurity agencies, beyond CISA and Canada’s Cyber Centre, are likely to issue their own advisories for CVE-2026-94127 as European and Asia-Pacific regulators catch up on the disclosure.
  • F5 will likely face scrutiny over its advisory cadence in 2026, given the volume of critical BIG-IP bugs disclosed this year, and enterprise customers may push for faster hotfix delivery windows in contract renewals.
  • CISA’s three-day KEV deadlines, now a repeated pattern for edge-device bugs, will likely become the de facto private-sector benchmark even without a legal mandate, simply because insurers and auditors increasingly reference KEV timelines in incident post-mortems.

Frequently Asked Questions

What is CVE-2026-94127?
It is a critical heap-based buffer overflow in F5 BIG-IP Access Policy Manager, rated CVSS 9.8 (v3.1) and 9.3 (v4.0), that allows an unauthenticated attacker to achieve remote code execution on affected appliances.

Which BIG-IP versions are affected?
F5 lists version 21.1.0, the 17.5.0 through 17.5.1 range, and 17.1.0 through 17.1.3 as vulnerable when APM is configured with an access policy and an OAuth profile acting as an OAuth Authorization Server.

Is CVE-2026-94127 actively exploited?
Yes. F5 stated in its advisory that it has learned the vulnerability has been exploited, and CISA added it to the Known Exploited Vulnerabilities catalog citing evidence of active exploitation.

What is the CISA patch deadline?
CISA’s KEV entry gives federal civilian agencies until September 25, 2026, to apply mitigations and complete forensic triage. That deadline is legally binding only for federal agencies, but CISA encourages all organizations to treat KEV entries with the same urgency.

How do I mitigate the flaw if I cannot patch immediately?
F5 published an interim iRule mitigation for exposed virtual servers. CISA’s guidance recommends applying that mitigation first, running forensic triage to check for prior compromise, then installing the branch-specific hotfix as soon as possible.

Is there a public exploit available?
Researchers had not confirmed a public proof-of-concept exploit at the time of F5’s disclosure, though that has changed quickly for comparable BIG-IP bugs in the past.

What other products were added to KEV the same day?
CISA’s September 22 update also added two Check Point vulnerabilities (CVE-2026-85102 and CVE-2026-93616) and one Arista VeloCloud Orchestrator vulnerability (CVE-2026-93952), all four rated unauthenticated and remotely exploitable.

Does this affect BIG-IP systems that only use APM as an OAuth Client?
No. F5 states that deployments using APM strictly as an OAuth Client or Resource Server, without an OAuth Authorization Server profile, are not affected by this vulnerability.