In brief: F5 confirms active attacks against CVE-2026-94127 in BIG-IP Access Policy Manager. The heap-based buffer overflow enables unauthenticated code execution, but not every APM deployment is exposed. A specific OAuth authorisation-server configuration on a virtual server is required.
Confirmed: RCE in the data plane
A virtual server is vulnerable when it combines an APM access policy with an OAuth profile and APM acts as an OAuth Authorization Server. Crafted network traffic can corrupt memory and execute code on the BIG-IP system. Deployments using APM only as an OAuth Client or Resource Server, without an authorisation-server profile, are not affected according to F5.
F5 lists BIG-IP APM 17.1.0 through 17.1.3, 17.5.0 through 17.5.1 and 21.1.0. Versions beyond technical support were not evaluated. CVE-2026-94127 scores 9.8 under CVSS 3.1 and 9.3 under CVSS 4.0. Appliance Mode does not protect the device. F5 classifies this as a data-plane issue; direct exposure of the management plane is unnecessary.
Engineering hotfixes are available for supported branches. Customers unable to patch immediately can obtain an iRule-based temporary mitigation from F5 Support. CERT-EU advises preserving forensic evidence before making changes, then applying the hotfix and checking for compromise.
Pandorex Analysis: version scanners are insufficient
The configuration dependency cuts both ways. A version-only inventory may flag too many systems, while an isolated management interface can create false confidence because attackers target the reachable data-plane virtual server. Internet-facing APM systems that issue OAuth tokens as authorisation servers deserve priority.
F5's traces should be assessed as a sequence: repeated OAuth invalid_token failures in /var/log/apm, an unexplained rise in total_failed, suspicious commands in /var/log/audit, then a TMM abort with SIGABRT. A TMM core alone does not prove exploitation. CERT-EU treats ten or more token failures from one IP in a short period as a reason for manual review.
Because exploitation preceded the public fix, “patched now” is not a complete response. Operators must investigate the pre-hotfix window and start incident response when evidence appears. NHS England's National CSOC explicitly assesses further exploitation as highly likely.
