Skip to content

CVE-2026-94127 explained: the F5 Big-ip Access Policy Manager flaw and how to fix it

By Donovan Brown
September 24, 2026
8 sections
CVE-2026-94127 explained: the F5 Big-ip Access Policy Manager flaw and how to fix it — Cyber Security article cover card from LayerLogix, with a warning alert icon
░
█
░ ▄ ■
▄▀■
■
01

Introduction

A newly published flaw in F5 Big-ip Access Policy Manager, tracked as CVE-2026-94127, lets an attacker take over the system without logging in. It is already listed on the government's catalog of vulnerabilities under active attack. If you run this software on the computer, phone or server in your office, keep reading.

02

Does this affect you?

The two-minute check

  1. Find the device or system your IT team calls the "APM" or "access policy manager" box. It is usually a dedicated appliance, not a regular desktop.
  2. Check whether it has an access policy and an OAuth profile configured on a virtual server. Your IT provider or system administrator will know this term; ask them directly if you are unsure.
  3. Confirm whether that access policy manager is set up as an OAuth Authorization Server, not just as an OAuth Client or Resource Server. The record says only the Authorization Server role is affected.

When you can stop reading

If you do not run F5 Big-ip Access Policy Manager anywhere in your business, this does not apply to you. The record also states that deployments using it strictly as an OAuth Client or Resource Server, without an OAuth authorization server profile configured, are not affected. If that matches your setup, you can close this tab.

03

How bad is it, honestly?

What the official record says

This flaw carries a Common Vulnerability Scoring System (CVSS) score of 9.8, rated CRITICAL (NVD). The scoring details say an attacker can reach it over a network, needs no special access conditions, requires no account or password, and needs no one to click anything. That combination means an outside attacker can try this directly against your system with no help from anyone inside your business.

The Exploit Prediction Scoring System (EPSS) score gives a 1.3% probability of exploitation in the next 30 days, which places it at the 69th percentile compared with other flaws (FIRST.org). The Exploit Prediction Scoring System (EPSS) is a forecast of exploitation activity in the near term, not a measure of how severe the flaw itself is.

This vulnerability is also on the Known Exploited Vulnerabilities (KEV) catalog maintained by the Cybersecurity and Infrastructure Security Agency (CISA KEV). That listing means criminals are already using this flaw against real systems, not just theorizing about it.

What that means for a business like yours

An unauthenticated attacker who reaches your access policy manager can run their own code on it. The record describes this as a data plane issue, meaning it affects the traffic passing through the device rather than its management console. If your access policy manager is public-facing, this is one of the more serious combinations you will see: no login needed, no click required, and active use in the wild.

04

What to do about it, step by step

If someone else manages your IT

Send your provider a short, direct message. You can paste this in:

  • "Do we run F5 Big-ip Access Policy Manager anywhere in our environment?"
  • "If so, please confirm whether it uses an OAuth Authorization Server profile."
  • "Please apply the fix described in the F5 vendor advisory for CVE-2026-94127 and confirm when it's done."

If you manage it yourself

  1. Log into the management console for your access policy manager.
  2. Locate the access policy and OAuth profile settings tied to your virtual servers.
  3. Confirm whether an OAuth Authorization Server profile is configured. If it is, treat this as urgent.
  4. Open the vendor advisory for CVE-2026-94127.
  5. Follow the guidance in that advisory for your specific setup. The fact sheet does not list a specific fixed version, so check the advisory directly for the current guidance.
  6. Restart or reload the configuration as instructed by the advisory, then confirm the system comes back online normally.
05

How long you have

The answer is now. This flaw was added to the CISA Known Exploited Vulnerabilities catalog on the day it was published, with a federal remediation deadline of September 25, 2026. That deadline applies to federal agencies directly, but it is a useful marker for everyone. Criminals are already using this flaw, so waiting does not lower your risk.

06

How to check it actually worked

Do not trust a progress bar alone. After applying the vendor's fix, go back into the access policy manager console and confirm the version or patch level shown matches what the advisory describes as current. Ask whoever applied the fix to show you the confirmation screen or log entry. If you have a managed IT provider, ask them to document the before-and-after state in writing.

07

What to do if you can't patch right now

If you cannot apply the fix immediately, you have some interim options, though none of them replace patching. Restricting network access to the affected virtual server, so only trusted internal addresses can reach it, reduces who can attempt an attack. It does not remove the underlying flaw. Disabling the OAuth Authorization Server profile, if your business does not strictly need it active right now, removes the specific condition the record says is required for this vulnerability. Confirm with whoever manages your applications before doing this, since it may affect authentication for other systems. Neither step is a substitute for applying the vendor's fix as soon as you can.

08

Frequently Asked Questions

Do I have to do anything if we only use this at home?

F5 Big-ip Access Policy Manager is enterprise-grade software typically run by businesses, not home users. If you are not sure whether your business runs it, ask your IT provider or check the device labels described earlier in this guide.

Will patching break anything?

The record does not say. Any change to an access policy manager configuration can affect how users authenticate, so test the change in a maintenance window if you can, and have a rollback plan ready.

What if we only use the OAuth Client or Resource Server role?

According to the record, that configuration is not affected by this vulnerability. You should still confirm this with whoever manages your configuration, since settings can change over time.

The record names only F5 Big-ip Access Policy Manager. It does not mention any other product, so this guide does not extend the risk beyond what is documented.

What if we don't have in-house IT staff?

A managed IT services provider can check your systems, apply the fix, and confirm it worked. If you also want a broader look at your exposure, a cybersecurity review can help identify similar gaps elsewhere in your environment.

LayerLogix brings 20+ years of experience and 100% Texas-based support to businesses across The Woodlands, Round Rock, Greater Houston, DFW, and Austin. If you want a clear answer on whether CVE-2026-94127 touches your business, request a free IT assessment or contact us today.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call