www.securityweek.com 23 Sept 2026, 07:34 UTC

F5 BIG-IP APM zero-day lets attackers execute code remotely

F5 BIG-IP APM zero-day lets attackers execute code remotely
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

F 5 and the US Cybersecurity and Infrastructure Security Agency (CISA) have warned that attackers are exploiting a critical BIG-IP Access Policy Manager (APM) vulnerability as a zero-day. Tracked as CVE-2026-94127, and rated 9.8 under CVSS, the flaw can allow unauthenticated attackers to execute code remotely through malicious traffic. It is exploitable when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server.

F5 said it discovered the defect internally and has confirmed that it has been exploited. The company said the vulnerability affects deployments where BIG-IP APM operates as an OAuth Authorization Server, but not configurations using APM as an OAuth Client or Resource Server. Appliance-mode systems are also vulnerable. F5 described it as a data-plane issue, with no control-plane exposure.

Affected versions are BIG-IP APM 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3. F5 has issued hotfixes and published three indicators of compromise, advising that their combined and repeated appearance should be correlated when investigating possible attacks. No other F5 products are affected, according to the company. CISA has added CVE-2026-94127 to its Known Exploited Vulnerabilities catalogue and directed US federal agencies to apply the fix within three days under Binding Operational Directive 26-04.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline