F5 Patches Critical BIG-IP APM Zero-Day Exploited in Attacks
Share
F5 has released security updates to address a critical zero-day vulnerability in its BIG-IP Access Policy Manager (APM) that is currently being exploited for remote code execution (RCE) attacks.
The vulnerability, tracked as CVE-2026-94127, affects instances configured as an OAuth Authorisation Server. The flaw specifically impacts deployments where a BIG-IP APM access policy and an OAuth profile are configured on a virtual server.
CISA Mandates Federal Remediation
The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalogue. Following this, CISA has ordered U.S. federal agencies to secure their networks against the flaw by Friday.
The agency warned that these types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Mitigation and Indicators of Compromise
F5 stated that deployments using APM strictly as an OAuth Client or Resource Server—without OAuth authorisation server profiles configured—are not affected by this vulnerability.
For administrators unable to apply the security updates immediately, F5 has provided a mitigation measure involving an iRule for the affected virtual servers. The company also advised customers to review systems for specific indicators of compromise.
Potential signs of exploitation include a combination of multiple OAuth authentication failures and suspicious commands, shortly followed by a TMM SIGABRT error.
The Internet threat monitoring non-profit Shadowserver is currently tracking over 14,700 IP addresses with BIG-IP APM fingerprints, though the number of systems already patched or acting as honeypots is unknown.
History of Targeted Attacks
F5 products have been a recurring target for cybercrime and state-backed threat groups. In October 2025, the company disclosed that state-sponsored hackers had breached its systems in August 2025, stealing undisclosed BIG-IP security source code and vulnerabilities.
Since November 2021, CISA has flagged eight actively exploited F5 vulnerabilities, four of which have been abused in ransomware attacks.




Leave a Reply