In short: On 22 September 2026, F5 patched a critical vulnerability, CVE-2026-94127 (CVSS 9.8), in BIG-IP Access Policy Manager (APM) — a heap-based buffer overflow in the OAuth component that lets a remote attacker execute arbitrary code with no authentication whatsoever. CISA added the bug to its Known Exploited Vulnerabilities catalog and gave U.S. federal agencies three days to fix it. BIG-IP APM is the gateway thousands of companies use to control employee remote access to internal systems, so this hole reaches far beyond F5 itself — to everyone whose data passes through gateways like it.
What happened
F5 is one of the largest network infrastructure vendors serving corporations and government agencies; its BIG-IP APM acts as an access controller — verifying user identity, enforcing security policy, and deciding who gets into a company's internal systems, functioning much like a corporate VPN gateway. On 22 September 2026, the company released emergency hotfixes for CVE-2026-94127, a heap-based buffer overflow rated 9.8 out of 10 on the CVSS scale. The flaw appears when a virtual server has both an APM access policy and an OAuth profile configured as an authorization server: specially crafted traffic to that server triggers the overflow and allows code execution without a single login attempt.
Already under attack
This is not a theoretical risk. "We have learned that this vulnerability has been exploited," F5 said in its advisory. That same day, 22 September, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog and ordered federal civilian agencies to remediate it by 25 September 2026 — a three-day deadline that signals attacks are happening right now. Details on the specific threat actors and campaign scope have not been disclosed. Affected versions include BIG-IP APM 17.1.0–17.1.3, 17.5.0–17.5.1, and 21.1.0.
Why this matters beyond IT teams
BIG-IP APM sits at the edge of a corporate network at exactly the point where employees and customers log into systems holding your personal data, payments, medical records, or messages. Taking over that gateway with no password at all means an attacker can bypass the entire authentication layer at once — not by guessing passwords one by one, but by sending a single malicious request. It's the same class of risk we saw in the Check Point firewall authentication bypass: the bigger the infrastructure choke point, the higher the cost of one unpatched hole for everyone whose data flows through it.
How to protect yourself
If you're an administrator. F5 has released engineering hotfixes for every affected version, plus a temporary iRule mitigation for those who cannot patch immediately (available through F5 Support). Check logs for repeated OAuth authentication failures and abnormal TMM behavior — F5 lists these as indicators of compromise.
If you're an everyday user. You cannot patch someone else's corporate gateway directly, but the same principle applies: keep every device and app updated, use unique passwords with two-factor authentication, and never rely on a single line of defense. On untrusted networks — public Wi-Fi, someone else's router — encrypt your own traffic independently of corporate infrastructure. LiMP VPN for iOS and Android builds an encrypted tunnel and keeps no connection logs — that doesn't replace a company's duty to patch its servers, but it does protect your own communication channel. Learn more on the LiMP VPN features page.
Sources
- BleepingComputer — F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks (September 2026)
- The Hacker News — F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers (September 2026)
- Rambler News — "F5 BIG-IP breached without a password" (September 2026, RU)
- Habr — InfoSec Digest, 15–22 September (September 2026, RU)
