F5 released patches for a critical zero-day vulnerability in BIG-IP Access Policy Manager (APM) after active exploitation by threat actors in the wild.

The flaw, tracked as CVE-2026-94127, allows unauthenticated attackers to execute arbitrary code on vulnerable BIG-IP systems. The vulnerability specifically affects installations where BIG-IP APM operates as an OAuth authorization server, meaning the device issues access tokens to applications and manages authentication flows. F5 published the advisory on September 22 and released engineering hotfixes to remediate the issue.

The attack requires no authentication. An attacker with network access to the APM interface can trigger code execution directly, bypassing login requirements entirely. This represents a severe risk for organizations relying on F5 BIG-IP as a critical authentication and access control layer.

F5 BIG-IP APM serves as a centralized access gateway for many enterprises, handling Single Sign-On (SSO), multi-factor authentication, and token issuance across internal and external applications. Deployment as an OAuth authorization server is common in organizations running cloud applications, SaaS platforms, and microservices architectures. Compromise of such a system grants attackers control over identity infrastructure, enabling them to forge access tokens, impersonate legitimate users, and move laterally across connected applications.

The active exploitation window remains unclear, though the September 22 disclosure suggests threat actors detected and weaponized the vulnerability before public announcement. Organizations operating BIG-IP APM in OAuth configurations face immediate risk. The scope of exploitation is not yet disclosed by F5 or independent researchers.

The CVE-2026-94127 designation indicates a 2026 publication year, which typically results from coordinated disclosure delays. This timing suggests F5 negotiated a grace period with vulnerability reporters before making the flaw public.

F5 recommends immediate patching for all affected BIG-IP versions. Organizations unable to apply patches immediately should isolate APM systems from untrusted networks or disable OAuth server functionality if not required. Network segmentation and access control lists (ACLs) limiting connections to the management interface provide temporary mitigation.

Security teams managing BIG-IP deployments should verify whether their systems use APM in OAuth configurations. Asset discovery tools and network scanning can identify these systems. Reviewing BIG-IP logs for unusual authentication failures, unexpected token issuance, or administrative access attempts may reveal prior exploitation attempts.

This vulnerability joins a history of critical BIG-IP flaws. Previous CVEs, including CVE-2020-5902 and CVE-2021-22986, exposed the platform to remote code execution and have been exploited extensively in the field. Defenders treating F5 BIG-IP as a critical security boundary should maintain current patch levels and monitor for anomalous behavior.

F5 customers should prioritize this patch in their maintenance schedules. The combination of zero-day status, active exploitation, and the sensitive nature of OAuth infrastructure makes rapid remediation essential for protecting authentication and access control systems.