A Critical BIG-IP APM Zero-Day Flaw Has Been Exploited in Remote Code Execution Attacks
F5, a leading cybersecurity company, has released urgent security updates to address a critical vulnerability in its BIG-IP Access Policy Manager (APM) solution. The zero-day flaw, tracked as CVE-2026-94127, allows attackers to execute remote code, putting thousands of organizations at risk.
BIG-IP APM is a centralized access management proxy that helps administrators secure network and application access. However, when configured with both an access policy and an OAuth profile on a virtual server, the vulnerability becomes exploitable. F5 warns that deployments using APM solely as an OAuth Client/Resource Server are not affected by this flaw.
The company has confirmed that the vulnerability has been exploited in attacks, and it advises customers to review their systems for indicators of compromise if they detect unusual patterns such as multiple OAuth authentication failures followed by suspicious commands or a TMM SIGABRT error. In the meantime, F5 recommends applying an iRule available through its support portal to mitigate the issue.
The scale of the vulnerability is concerning, with over 14,700 IP addresses tracked by Shadowserver displaying BIG-IP APM fingerprints. However, it’s unclear how many of these have been patched or are honeypots. The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, ordering federal agencies to secure their networks against this flaw by Friday.
F5’s vulnerability is the latest in a string of security issues affecting the company’s products. Threat groups have exploited F5 vulnerabilities in recent years, targeting corporate networks, hijacking devices, mapping internal servers, deploying malware, and stealing sensitive documents. In 2025, state-sponsored hackers breached F5 systems, stealing BIG-IP security source code and vulnerabilities.
The importance of patching critical vulnerabilities cannot be overstated. With the increasing sophistication of cyber threats, it’s essential for organizations to stay vigilant and address vulnerabilities promptly. This includes not only applying security updates but also reviewing systems regularly for signs of compromise. By taking proactive steps to secure their networks, organizations can minimize the risk of being exploited by malicious actors.
As a practical takeaway, we recommend that administrators review their BIG-IP APM configurations immediately and apply the necessary patches or mitigations as soon as possible. This includes applying the iRule provided by F5 Support and reviewing systems for signs of compromise. By staying ahead of potential threats, organizations can protect themselves against the evolving landscape of cyber attacks.
Source: Bleeping Computer — 2026-09-23