Summary
- CVE-2026-94127 affects specified BIG-IP APM versions when APM is configured as an OAuth authorisation server.
- Successful exploitation can give an unauthenticated attacker remote-code execution on the affected appliance.
- F5 has observed exploitation in the wild, while NHS England’s National CSOC assesses further exploitation as highly likely.
A critical vulnerability in F5 BIG-IP Access Policy Manager is being exploited in the wild, exposing certain internet-facing access systems to unauthenticated remote-code execution.
CVE-2026-94127 is a heap-based buffer-overflow vulnerability with a CVSS v4 base score of 9.3. NHS England Digital issued an alert on 23 September after F5 confirmed that it was aware of exploitation.
The vulnerability does not affect every BIG-IP APM deployment. Exposure requires an APM access policy and OAuth profile configured with BIG-IP APM acting as an OAuth authorisation server. Deployments using APM solely as an OAuth client or resource server, without the affected authorisation-server profile, are not vulnerable to this issue.
Affected versions include BIG-IP APM 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0, according to the NHS alert. F5 does not assess products that have reached end of technical support, so unsupported systems require separate consideration rather than being assumed safe.
Successful exploitation can allow an unauthenticated attacker to execute code against the affected device. F5 describes the issue as affecting the data plane rather than exposing the control plane, but remote execution on an edge access platform still creates a serious route into environments that may rely on the appliance for authentication and remote connectivity.
NHS England’s National Cyber Security Operations Centre assesses further exploitation as highly likely. The alert urges affected organisations to review F5’s advisory and apply the relevant update.
Internet-facing security appliances have become a persistent initial-access target because they combine external exposure with privileged positions inside networks. VPNs, secure access gateways, firewalls, and remote-management products may terminate authenticated sessions, inspect traffic, or bridge external users into internal services.
That means a flaw in the edge control itself can bypass some of the protections organisations expect the device to provide. Attackers have repeatedly moved quickly against vulnerabilities in perimeter products, including newly disclosed flaws and weaknesses for which patches exist but have not yet been deployed.
The configuration dependency in CVE-2026-94127 also illustrates why vulnerability management cannot be reduced to matching product names against CVE lists. An organisation needs to know not only whether it operates BIG-IP APM and which version is installed, but which roles and profiles are active on each exposed system.
That inventory becomes harder in large environments where appliances have accumulated configuration changes over several years or where regional teams operate infrastructure independently. Unsupported devices further complicate remediation because a vulnerability may sit outside the vendor’s current evaluation scope.
The immediate response is a vendor-update problem, but the broader resilience issue concerns edge infrastructure lifecycle management. Organisations that depend on remote-access and identity gateways need reliable visibility of versions, configurations, support status, external exposure, and contingency options when an emergency update affects a critical service.
F5 has confirmed exploitation, but neither F5 nor the NHS alert identifies specific victim organisations or attributes the activity to a threat group. Claims beyond the confirmed vulnerability, affected configuration, and observed exploitation should therefore remain separate from the evidence presently available.





