F5 has released urgent security updates to fix a critical zero-day vulnerability in its BIG-IP APM (Access Policy Manager) solution, which is being actively exploited in remote code execution attacks. The flaw, tracked as CVE-2026-94127, affects instances configured as an OAuth Authorization Server, allowing attackers to execute malicious code and potentially gain unauthorized access to sensitive data.
The vulnerability impacts organizations that use BIG-IP APM to secure access to their networks, applications, cloud services, and APIs. F5’s centralized access management proxy solution is designed to help administrators control user access and ensure the security of their organization’s assets. However, in this case, a configuration weakness has been exploited by attackers, who can bypass authentication and execute arbitrary code.
F5 has warned that deployments using APM strictly as an OAuth Client/Resource Server are not affected by this vulnerability. However, for instances configured as an OAuth Authorization Server, administrators must take immediate action to patch the flaw. The company recommends reviewing systems for indicators of compromise, such as multiple OAuth authentication failures and suspicious commands, followed by a TMM SIGABRT.
Fortunately, F5 has provided mitigation measures for admins who cannot immediately install the security updates. These include applying an iRule to the affected BIG-IP APM virtual server. Customers can obtain this iRule from F5 Support. It is essential to note that delaying patching will leave organizations vulnerable to attacks, and administrators should prioritize installing the latest security updates as soon as possible.
The impact of this vulnerability extends beyond individual organizations, as it has been added to the US Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities Catalog. This means that federal agencies in the US have been ordered to secure their networks against this flaw by Friday. The CISA warning highlights the significant risks posed by vulnerabilities like CVE-2026-94127, which are frequently exploited by malicious actors.
This is not an isolated incident; F5 has faced numerous security breaches in recent years, with threat groups exploiting vulnerabilities in its products to breach corporate networks, hijack devices, and steal sensitive documents. In fact, state-sponsored hackers breached F5’s systems last year, stealing undisclosed BIG-IP security source code and vulnerabilities.
For organizations using F5 BIG-IP APM solutions, it is crucial to prioritize patching the CVE-2026-94127 vulnerability as soon as possible. This involves installing the latest security updates and reviewing systems for indicators of compromise. Additionally, administrators should consider implementing additional security measures, such as monitoring for suspicious activity and ensuring that all software and firmware are up-to-date.
In conclusion, the F5 BIG-IP APM zero-day flaw serves as a reminder of the importance of timely patching and vulnerability management in today’s threat landscape. Organizations must stay vigilant and take proactive steps to protect themselves against emerging threats.
Source: Bleeping Computer — 2026-09-23