Overview
- F5 disclosed a heap-based buffer overflow tracked as CVE-2026-94127 and said the bug has been exploited in the wild after Tuesday's advisory, and the company published engineering hotfixes for the affected 21.1, 17.5 and 17.1 branches.
- The vulnerability permits unauthenticated attackers to run code by sending crafted OAuth traffic to a virtual server where APM is configured as an OAuth authorization server with an APM access policy and OAuth profile on the same virtual server.
- CISA added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to apply mitigations quickly, while F5 provided an iRule mitigation and published indicators of compromise for triage.
- Operators are warned that restricting management-interface access does not stop attacks because the exploit targets the BIG-IP data plane, that Appliance mode is vulnerable, and that installing the hotfix may not evict attackers who already have access.
- Security bodies including CERT-EU advise preserving forensic evidence before patching, checking for repeated OAuth UserInfo failures and TMM SIGABRT/core activity, and investigators note the number of victims and attacker identities remain unknown with prior APM exposures adding broader risk context.