BREAKING NEWSBREAKING: ASOS Confirms Customer Data May Have Been Accessed in Cyber Incident
Monitoring active · Brevard County, Florida

A3E Cyber Blog

BREAKING: F5 BIG-IP APM Zero-Day Exploited for Unauthenticated Remote Code Execution

F5 has disclosed that attackers are actively exploiting CVE-2026-94127, a critical vulnerability in certain BIG-IP Access Policy Manager deployments. The flaw can allow an unauthenticated attacker to execute code on a vulnerable BIG-IP system by sending malicious traffic to an affected virtual server.

What is confirmed

F5 says it has learned that CVE-2026-94127 has been exploited in the wild. SecurityWeek and BleepingComputer reported on September 23 that F5 released engineering hotfixes after disclosing the issue. The vulnerability carries a CVSS v3.1 score of 9.8.

The affected configuration is specific: BIG-IP APM must have an access policy and an OAuth authorization server profile configured on the same virtual server. F5 says deployments using APM strictly as an OAuth Client or Resource Server, without OAuth authorization server profiles, are not affected by this vulnerability.

Why CVE-2026-94127 is urgent

The vulnerability is especially serious because exploitation does not require authentication. A remote attacker able to send crafted traffic to a vulnerable deployment may be able to achieve remote code execution on the BIG-IP system.

CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. That designation is a strong signal for organizations to prioritize remediation rather than treating the issue as a routine patch-cycle item.

Which BIG-IP deployments are affected

According to F5 reporting summarized by SecurityWeek, affected releases include BIG-IP APM 21.1.0, versions 17.5.0 through 17.5.1, and versions 17.1.0 through 17.1.3 when the vulnerable OAuth authorization server configuration is present. Administrators should verify their exact version and configuration against current F5 guidance before assuming a system is safe.

What organizations should do now

Administrators running BIG-IP APM should immediately determine whether any virtual server combines an APM access policy with an OAuth authorization server profile. If so, apply the engineering hotfix or other remediation provided by F5 as quickly as operationally possible.

Organizations should also review F5’s published indicators of compromise, inspect relevant BIG-IP telemetry for suspicious activity, preserve logs for investigation, and treat evidence of unexpected code execution or unusual traffic as a potential incident. Because exploitation has already been observed, patching alone should not replace a review for prior compromise.

What remains unknown

Public reporting has not established the identity of the attackers, the number of organizations compromised, or the full scope of activity associated with exploitation. Those details should not be inferred from the existence of the vulnerability alone.

Why this matters beyond F5 customers

Internet-facing access infrastructure is a high-value target because compromise can provide attackers a path toward applications and internal resources. Organizations should maintain an inventory of exposed edge systems, monitor vendor security advisories, and have an emergency process for vulnerabilities confirmed to be under active exploitation.

Sources

SecurityWeek: Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

BleepingComputer: F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

The Hacker News: F5 Patches Critical BIG-IP APM Zero-Day

Next step

Want this checked on your own systems?

The assessment is free and the summary is yours to keep either way.

Leave a comment

Your email address will not be published. Required fields are marked *

Call now Book an assessment