Critical F5 BIG-IP exploit: CVE-2026-94127 #

F5 disclosed a critical OAuth remote code execution (RCE) vulnerability affecting select versions of BIG-IP APM. When an access policy and an OAuth profile are configured on a virtual server, crafted malicious traffic can trigger a heap-based buffer overflow, allowing an unauthenticated attacker to execute arbitrary code remotely. This vulnerability has been designated CVE-2026-94127 and has been rated critical with a CVSS score of 9.8.

There is evidence that this vulnerability is being actively exploited in the wild, and it was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026.

The following versions are affected:

  • BIG-IP 21.1.x: Versions in the 21.1.0 release branch prior to the vendor-supplied engineering hotfix
  • BIG-IP 17.5.x: Versions in the 17.5.0 release branch prior to the vendor-supplied engineering hotfix
  • BIG-IP 17.1.x: Versions in the 17.1.0 release branch prior to the vendor-supplied engineering hotfix

What is F5 BIG-IP Access Policy Manager (APM)? #

F5 BIG-IP Access Policy Manager (APM) is a module that provides secure, context-aware access control for applications and networks, including support for OAuth-based authentication and authorization profiles.

What is the impact? #

Successful exploitation of this vulnerability would allow a remote, unauthenticated attacker to execute arbitrary code on the vulnerable host, potentially leading to complete system compromise.

Are any updates or workarounds available? #

Upgrade affected versions of F5 BIG-IP Access Policy Manager to the latest patched version.

  • BIG-IP 21.1.x: Apply Hotfix-BIGIP-21.1.0.2.0.30.22-ENG or later.
  • BIG-IP 17.5.x: Apply Hotfix-BIGIP-17.5.1.9.0.160.12-ENG or later.
  • BIG-IP 17.1.x: Apply Hotfix-BIGIP-17.1.3.5.0.41.14-ENG or later.

Note: F5 has confirmed an iRule mitigation is available upon request by opening a ticket with F5 support, for use as a temporary mitigation while the engineering hotfix is applied.

      Finding exposed F5 Big-IP systems with runZero #

      From the Software Inventory, use the following query to locate potentially affected systems:

      vendor:=F5 AND product:="BIG-IP Access Policy Manager"

      March 2026: CVE-2025-53521 #

      On October 15, 2025, F5 disclosed a denial of service vulnerability, designated CVE-2025-53521, in F5 BIG-IP Access Policy Manager (APM).

      On Friday, March 27, 2026, F5 updated the CVE entry to indicate that the vulnerability is now known to be a remote code execution vulnerability (RCE) with a CVSS score of 9.8. This vulnerability is now known to allow a remote, unauthenticated attacker to perform remote code execution.

      This vulnerability is known to be exploited in the wild and was added to the CISA.gov Known Exploited Vulnerabilities (KEV) list on March 27, 2026.

      The following versions are affected:

      • F5 BIG-IP Access Policy Manager versions 17.5.0 - 17.5.1 (inclusive)
      • F5 BIG-IP Access Policy Manager versions 17.1.0 - 17.1.2 (inclusive)
      • F5 BIG-IP Access Policy Manager versions 16.1.0 - 16.1.6 (inclusive)
      • F5 BIG-IP Access Policy Manager versions 15.1.0 - 15.1.10 (inclusive)

      What is the impact? #

      Successful exploitation of this vulnerability would allow a remote, unauthenticated attacker to execute arbitrary code on the vulnerable host, potentially leading to complete system compromise.

      Are any updates or workarounds available? #

      Upgrade affected versions of F5 BIG-IP Access Policy Manager to the latest patched version.

      • 17.5.x upgrade to 17.5.1.3 or later
      • 17.1.x upgrade to 17.1.3 or later
      • 16.1.x upgrade to 16.1.6.1 or later
      • 15.1.x upgrade to 15.1.10.8 or later

          How do I find F5 Big-IP assets with runZero? #

          From the Software Inventory, use the following query to locate potentially affected systems:

          vendor:=F5 AND product:="BIG-IP Access Policy Manager"

          October 2025: CISA Emergency Directive #

          On October 15, 2025, CISA issued an emergency directive to mitigate vulnerabilities on F5 Big-IP appliances. According to the directive, the general guidance is to "inventory F5 BIG-IP products, evaluate if the networked management interfaces are accessible from the public internet, and apply newly released updates from F5."

          What is the impact? #

          According to the directive, "a nation-state affiliated actor compromised F5 systems and exfiltrated data, including portions of the Big-IP proprietary source code and vulnerability information". The emergency directive specifically calls out "all instances of F5 BIG-IP hardware devices and F5OS, BIG-IP TMOS, Virtual Edition, BIG-IP Next, BIG-IP IQ software, and BNK / CNF". Organizations should apply the latest vendor updates and disconnect any affected publicly-connected devices that have reached their end-of-support date.

          For more information, refer directly to the CISA emergency directive. 

            How do I find F5 Big-IP assets with runZero? #

            From the Asset Inventory, use the following query to locate potentially affected systems:

            os:="F5%"

            May 2022: CVE-2022-1388 #

            In May 2022, technology vendor F5 published information on over 40 vulnerabilities, mostly affecting their BIG-IP line of products. While these vulnerabilities included a mix of types and severities, a particular authentication bypass vulnerability that affected all BIG-IP modules was concerning enough that CISA specifically called it out.

            What was the impact? #

            Known as CVE-2022-1388 (CVSS “critical” score of 9.8), a vulnerable BIG-IP target could allow for takeover by an unauthenticated attacker via network connection or management port. Once connected to a vulnerable target, successful exploitation was achieved via a crafted HTTP request sent by the attacker, bypassing iControl REST authentication and providing the attacker full access and control. F5 did add that there was no data plane exposure via exploitation of this vulnerability, rather "this being a control plane issue only".

            Were updates available? #

            Patches were made available by F5 for CVE-2022-1388, as well for many of the other vulnerabilities included in their security advisory overview. Guidance also included mitigation steps if immediate or near-term patching was not an option.

            Written by Tom Sellers

            Tom Sellers is a Principal Research Engineer at runZero. In his 25 years in IT and Security he has built, broken, and defended networks for companies in the finance, service provider, and security software industries. He has built and operated Internet scale scanning and honeypot projects. He is credited on many patents for network deception techonology. A strong believer in Open Source he has contributed to projects such as Nmap, Metasploit, and Recog.

            More about Tom Sellers

            Written by runZero Team

            Great research and development is a team effort! Multiple runZero team members collaborated on this post. Go team!

            More about runZero Team

            Written by Matthew Kienow

            Matthew Kienow is a software engineer and security researcher. Matthew previously worked on the Recog recognition framework, AttackerKB as well as Metasploit's MSF 5 APIs. He has also designed, built, and successfully deployed many secure software solutions; however, often he enjoys breaking them instead. He has presented his research at various security conferences including DerbyCon, Hack In Paris, and CarolinaCon. His research has been cited by CSO, Threatpost and SC Magazine.

            More about Matthew Kienow
            Subscribe Now

            Get the latest news and expert insights delivered in your inbox.

            Welcome to the club! Your subscription to our newsletter is successful.

            Explore more runZero

            Product
            runZero 5.1 is here: Secure AI workflows, enhanced integrations, and expanded autonomous discovery
            runZero 5.1 takes on the heavy lifting across five key areas, enabling you to unmask and remediate exposures with less friction and more speed.
            Podcasts
            Know Your Adversary with HD Moore
            runZero CEO HD Moore breaks down the myth of air-gapped networks, the impact of AI on security, and why asset connectivity is everything.
            runZero Perspective
            BOD 26-04: A new era of prioritized remediation
            A complete breakdown of CISA's BOD 26-04 directive. Learn how the shift to SSVC, risk-based KEV prioritization, and 3-day remediation impacts your...
            runZero Perspective
            Dawn of the apex agentic adversary
            When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
            Webcasts
            runZero Hour, Ep. 34: Vulnerability vibes: Disclosures, meetups, and the AI evolution
            Watch the runZero Hour replay: separating AI "slop" from real vulnerability insights, running local hacker meetups, and analyzing the top monthly...
            Product Videos
            Custom integrations at AI speed
            Build custom exposure management integrations on your terms. runZero 5.1 lets you leverage your choice of AI to create, adapt, and secure your...
            Webcasts
            runZero Hour, Ep. 33: Hacker Summer Camp: we survived the Vegas heat (and the bugs)
            In this post-Hacker Summer Camp recap, the runZero team break down the research, tools, and trends discussed at BSides Las Vegas, Black Hat and DEF...
            Podcasts
            The Internet's biggest point of failure
            Join Tod Beardsley on Secure & Scale as he explores the future of vulnerability management, CVE fragmentation, and how AI is changing security...

            See Results in Minutes

            See & secure your total attack surface. Even the unknowns & unmanageable.