Download Privacy Needle App

Type to search

Cybersecurity

F5 Patches Critical BIG-IP APM Zero-Day Exploited in Attacks

Share

F5 has released security updates to address a critical zero-day vulnerability in its BIG-IP Access Policy Manager (APM) that is currently being exploited for remote code execution (RCE) attacks.

The vulnerability, tracked as CVE-2026-94127, affects instances configured as an OAuth Authorisation Server. The flaw specifically impacts deployments where a BIG-IP APM access policy and an OAuth profile are configured on a virtual server.

CISA Mandates Federal Remediation

The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalogue. Following this, CISA has ordered U.S. federal agencies to secure their networks against the flaw by Friday.

The agency warned that these types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

Mitigation and Indicators of Compromise

F5 stated that deployments using APM strictly as an OAuth Client or Resource Server—without OAuth authorisation server profiles configured—are not affected by this vulnerability.

For administrators unable to apply the security updates immediately, F5 has provided a mitigation measure involving an iRule for the affected virtual servers. The company also advised customers to review systems for specific indicators of compromise.

Potential signs of exploitation include a combination of multiple OAuth authentication failures and suspicious commands, shortly followed by a TMM SIGABRT error.

The Internet threat monitoring non-profit Shadowserver is currently tracking over 14,700 IP addresses with BIG-IP APM fingerprints, though the number of systems already patched or acting as honeypots is unknown.

History of Targeted Attacks

F5 products have been a recurring target for cybercrime and state-backed threat groups. In October 2025, the company disclosed that state-sponsored hackers had breached its systems in August 2025, stealing undisclosed BIG-IP security source code and vulnerabilities.

Since November 2021, CISA has flagged eight actively exploited F5 vulnerabilities, four of which have been abused in ransomware attacks.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.