F5 has released engineering hotfixes for a critical zero-day vulnerability in BIG-IP Access Policy Manager (APM) that attackers are actively exploiting for unauthenticated remote code execution. The flaw, CVE-2026-94127, is a heap-based buffer overflow rated 9.8 out of 10 on the CVSS v3.1 scale. F5 disclosed the issue on September 22, and CISA added it to the Known Exploited Vulnerabilities catalog the same day, giving federal agencies until September 25 to apply mitigations.
The vulnerable configuration is specific: APM must be serving as an OAuth authorization server, with an APM access policy and an OAuth authorization server profile on the same virtual server. Malicious traffic sent to that virtual server can trigger code execution, so restricting access to the BIG-IP management interface does not block the attack. F5 initially described the condition broadly, then updated its CVE record to narrow it to the authorization server role; earlier advisories from CISA and CERT-EU describe the affected setup in broader terms.
Hotfixes are available for the 21.1, 17.5, and 17.1 branches, and F5 also offers an iRule mitigation for customers who cannot install the hotfix immediately. The shorter reports from SecurityWeek and BleepingComputer agree on the core facts: the flaw is a critical BIG-IP APM zero-day and is being exploited in RCE attacks. They do not provide the configuration-specific details or the narrower scope described in The Hacker News. F5 has not confirmed whether applying the hotfix removes access an attacker may have already gained.