F5 announce a critical flaw

F5 annouce a Critical Flaw sitting in front of your data center.

F5 annouce a Critical Flaw sitting in front of your data center.

F5 announce a critical flaw

F5 discloses a critical vulnerability

Tracked as CVE-2026-94127, in it’s BIG-IP Access Policy Manager on September 22, warning that attackers are already exploiting it in the wild. The flaw lets an unauthenticated attacker execute code on a BIG-IP system without logging in — but only on systems where APM is configured as an OAuth authorization server, issuing access tokens to connected applications.

BIG-IP appliances sit at the network edge of a huge share of enterprise and data center environments, functioning as load balancers, application delivery controllers, and access gateways — exactly the kind of chokepoint infrastructure that makes a single unauthenticated RCE flaw high-value to attackers. F5 has released engineering hotfixes but has not yet shipped a full patch, meaning affected operators are currently running on interim mitigations rather than a permanent fix.

The vulnerable configuration is specific

An APM access policy and an OAuth authorization server profile sharing the same virtual server — which narrows exposure but doesn’t eliminate it for any organization using BIG-IP APM for federated identity or API access control, both common patterns in enterprise data center deployments.

Why this matters for data center operators

This is a check-your-configuration-today problem, not a next-quarter roadmap item. Any facility running BIG-IP APM with OAuth authorization enabled should confirm exposure against F5’s advisory immediately, apply the hotfix, and treat the eventual full patch as mandatory-on-release rather than routine maintenance, active exploitation means the window between disclosure and attack has already closed.