F5 BIG-IP APM RCE flaw exploited in wild
An unauthenticated remote code execution vulnerability in F5 BIG-IP Access Policy Manager is being actively exploited in the wild.
MS-ISAC issued an advisory (2026-098) for CVE-2026-94127, a remote code execution vulnerability in F5 BIG-IP Access Policy Manager (APM). The flaw is triggered when a BIG-IP APM access policy with an OAuth profile is configured on a virtual server; specially crafted malicious traffic can lead to unauthenticated RCE. This is a data plane issue only, with no control plane exposure, but the BIG-IP system in Appliance mode is also vulnerable. F5 has confirmed active exploitation of this vulnerability in the wild.
Affected versions include BIG-IP APM 21.1.0, 17.5.0-17.5.1, and 17.1.0-17.1.3. Given BIG-IP APM's widespread deployment across government, financial services, healthcare, and large enterprises for network access and identity management, successful exploitation could grant an attacker full control of the affected system, including installing programs, modifying or deleting data, or creating new privileged accounts.
Defenders should apply F5's provided patches or workarounds immediately after testing, given confirmed in-the-wild exploitation. Standard hardening measures apply: least-privilege configuration, network segmentation to isolate management interfaces and critical systems, vulnerability scanning, and monitoring for anomalous traffic to virtual servers with OAuth-configured access policies.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-f5-big-ip-access-policy-manager-could-allow-for-remote-code-execution_2026-098
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free