F5 BIG-IP Access Policy Manager (APM) contains an actively exploited critical buffer-overflow vulnerability, CVE-2026-94127 (CVSS 9.8), that enables unauthenticated remote code execution. An attacker can send specially crafted traffic to a vulnerable virtual server configured with both an APM access policy and an OAuth profile; the flaw affects the data plane, including Appliance Mode deployments, but not the control plane.
Affected releases include BIG-IP APM 21.1.0, 17.5.x, and 17.1.x versions lacking the applicable engineering hotfixes. F5 and national cyber agencies urge administrators to install the vendor hotfixes immediately; an F5 iRule is available as a temporary mitigation. Defenders should investigate repeated OAuth failures, suspicious commands, and TMM SIGABRT crashes using F5’s compromise guidance, while treating any single indicator as insufficient evidence of compromise.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-949 concerning actively exploited CVE-2026-94127 and advised administrators to review F5 guidance and apply required updates.
F5 reported that CVE-2026-94127 was being exploited in the wild. The flaw can allow unauthenticated remote code execution against vulnerable BIG-IP APM virtual servers configured with both an access policy and an OAuth profile.
F5 received the CVE record for CVE-2026-94127, a critical buffer-overflow flaw in BIG-IP Access Policy Manager's OAuth component.
F5 published advisory K000162605 with engineering hotfixes for affected BIG-IP APM 21.1.0, 17.5.x, and 17.1.x releases, plus an iRule mitigation for cases where patching cannot immediately occur. It also provided indicators for investigating potential compromise, including repeated OAuth failures, suspicious commands, and TMM SIGABRT events.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourceacn.gov.it
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.