← All articles

F5 patches exploited BIG-IP APM zero-day allowing remote code execution on access proxies

F5 released updates for a critical BIG-IP Access Policy Manager zero-day that it confirms is being exploited in remote code execution attacks. Tracked as CVE-2026-94127, the flaw affects instances configured as an OAuth Authorization Server, where a BIG-IP APM access policy and an OAuth profile sit on the same virtual server. Deployments using APM strictly as an OAuth client or resource server are not affected. F5 told customers to hunt for multiple OAuth authentication failures and suspicious commands followed by a TMM SIGABRT, and offered an iRule mitigation for those who cannot patch immediately. Shadowserver tracks over 14,700 exposed BIG-IP APM instances, and CISA added the flaw to its catalog.

Check
Identify BIG-IP APM virtual servers configured as OAuth Authorization Servers, apply F5's update now, or deploy the iRule mitigation and check for compromise indicators.
Affected
BIG-IP APM instances acting as an OAuth Authorization Server with an access policy and OAuth profile on one virtual server face active remote code execution attacks.
Fix
Patch to F5's fixed BIG-IP releases, apply the iRule workaround if patching is delayed, and review logs for OAuth failures preceding a TMM SIGABRT.