securityaffairs.com 23 Sept 2026, 18:12 UTC

F5 Patches Exploited BIG-IP Flaw Allowing Unauthenticated Code Execution

F5 Patches Exploited BIG-IP Flaw Allowing Unauthenticated Code Execution
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

F 5 has released emergency updates for a critical BIG-IP Access Policy Manager (APM) vulnerability, CVE-2026-94127, which has a CVSS score of 9.8 and is being exploited in the wild. The flaw allows an unauthenticated attacker to execute arbitrary code through specially crafted traffic. It affects BIG-IP deployments where an APM access policy and OAuth profile are configured on a virtual server, with APM operating as an OAuth Authorisation Server.

Systems using APM only as an OAuth Client or Resource Server are not affected. F5 said the issue is in the data plane, not the management plane, and that appliance-mode systems are also vulnerable.

Affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0. F5 has issued hotfixes for the vulnerable branches and confirmed that exploitation has occurred. The company says defenders should look for repeated OAuth authentication failures followed by suspicious commands and, soon afterwards, a TMM SIGABRT event. Organisations that cannot install the update immediately can apply an iRule supplied through F5’s support channels, although this is only a temporary mitigation.

The US Cybersecurity and Infrastructure Security Agency added CVE-2026-94127 to its Known Exploited Vulnerabilities catalogue, giving US federal agencies until 25 September 2026 to address it. Shadowserver was tracking more than 14,700 IP addresses displaying BIG-IP APM fingerprints, though this does not show how many are vulnerable or unpatched.

F5 recommends checking whether the affected OAuth configuration is in use, identifying exposed systems, applying the relevant hotfix and reviewing logs for signs of compromise.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline