F5 BIG-IP APM zero-day exploited in wild
An actively exploited zero-day heap overflow in F5 BIG-IP Access Policy Manager allows unauthenticated remote code execution when OAuth is configured on a virtual server.
NCSC-NL has issued a high-priority advisory for CVE-2026-94127, a heap-based buffer overflow in F5 Networks BIG-IP Access Policy Manager (APM). The vulnerability allows an unauthenticated attacker to execute arbitrary code by sending crafted network traffic to a vulnerable system. Affected systems are those with both an access policy and an OAuth profile configured on the virtual server. F5 has confirmed this is a zero-day vulnerability that is being actively exploited in the wild, and has assigned it a CVSS v4 score of 9.3.
F5 has released security updates addressing the flaw along with indicators of compromise (IOCs). NCSC-NL strongly advises organizations to check vulnerable systems for the published IOCs before applying patches, given the ongoing active exploitation, and to prioritize this check and remediation as soon as possible. For organizations unable to apply updates immediately, F5 has published alternative mitigating measures. Defenders should consult F5's own advisory for the IOCs and detailed mitigation guidance, and treat any BIG-IP APM instance with OAuth-enabled access policies as high-risk until patched or verified clean.
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0386.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free