Back to Feed
VulnerabilitiesSep 23, 2026

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

Critical F5 BIG-IP vulnerability exploited as zero-day, allowing unauthenticated RCE.

Summary

F5 has issued a warning that threat actors are actively exploiting a critical vulnerability in its BIG-IP Access Policy Manager (APM) as a zero-day. The flaw, tracked as CVE-2026-94127 with a CVSS score of 9.8, allows unauthenticated attackers to achieve remote code execution when BIG-IP APM is configured with an OAuth profile. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch it within three days.

Full text

F5 and CISA on Tuesday warned organizations that threat actors have been exploiting a critical-severity BIG-IP Access Policy Manager (APM) vulnerability as a zero-day. The flaw is exploitable via malicious traffic sent to the appliance when “a BIG-IP APM access policy and an OAuth profile are configured on a virtual server,” F5 notes in its advisory. Tracked as CVE-2026-94127 (CVSS score of 9.8), the bug allows unauthenticated attackers to achieve remote code execution (RCE) on a vulnerable deployment. “We have learned that this vulnerability has been exploited,” F5 says, noting that it discovered the security defect internally. According to the company, the issue can be triggered only when BIG-IP APM is configured as an OAuth Authorization Server, not on deployments using APM as an OAuth Client/Resource Server. “The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure,” the company notes.Advertisement. Scroll to continue reading. BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 are vulnerable, and F5 has released hotfixes. No other products are vulnerable, the company says. Additionally, the company published three indicators of compromise (IoCs), noting that their combined and frequent appearance should be correlated to an attack. Just as F5 published its advisory, CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) list, urging federal agencies to patch it within three days, as mandated by BOD 26-04. Related: Check Point Patches Exploited Management Server Zero-Day Related: Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers Related: Malicious B-tree NPM Package Accumulates Millions of Downloads Related: AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire WordPress Patches ‘Click2Shell’ VulnerabilityFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ StealerRatHat Android Trojan Uses AI for AutomationCrowdSec Confirms Source Code Stolen in Supply Chain AttackOrganizations Warned of 3 Exploited Linux Kernel VulnerabilitiesTigerByte Cyber Emerges From Stealth With $3 Million in FundingNightmareStresser DDoS Service Disrupted in International OperationBrevo Supply Chain Attack Injects Malware Into 100,000 Websites Latest News ShinyHunters Claims FBI Hack, Demands Retraction of Threat ReportCheck Point Patches Exploited Management Server Zero-DayBigCommerce Data Stolen via Ribon Apps HackCyera Raises $400 Million at $12+ Billion ValuationNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing IdentityOnly 13% of OT Network Segments Are Fully Isolated: AnalysisRecent ZyXEL Switch Vulnerability Exploited by Chinese HackersMalicious B-tree NPM Package Accumulates Millions of Downloads Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-94127

Entities

BIG-IP APM (product)F5 (vendor)OAuth (technology)BIG-IP (product)