Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

3012+ Articles
170+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. F5 Patches BIG-IP APM Zero-Day Flaw Exploited in RCE Attacks
F5 Patches BIG-IP APM Zero-Day Flaw Exploited in RCE Attacks
NEWS

F5 Patches BIG-IP APM Zero-Day Flaw Exploited in RCE Attacks

F5 patched CVE-2026-94127, a CVSS 9.8 BIG-IP APM zero-day already exploited for unauthenticated RCE; CISA added it to its KEV catalog.

Dylan H.

News Desk

September 23, 2026
3 min read

Actively Exploited Before the Patch Shipped

F5 disclosed and patched a critical zero-day vulnerability in BIG-IP Access Policy Manager (APM) that attackers were already exploiting for unauthenticated remote code execution. The flaw, tracked as CVE-2026-94127, carries a CVSS score of 9.8 and was published in F5 security advisory K000162605 on September 22, 2026.

F5 says it discovered the issue internally and has since confirmed it "has been exploited," though no public proof-of-concept has surfaced. CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog the same day and ordered federal civilian agencies to secure affected systems by Friday.


Vulnerability Summary

FieldDetails
CVE IDCVE-2026-94127
CVSS Score9.8 (Critical)
Vulnerability TypeHeap-based buffer overflow (CWE-122) leading to RCE
AdvisoryF5 K000162605
Exploitation StatusConfirmed exploited in the wild
CISA KEVAdded September 22, 2026

What's Actually Vulnerable

The bug only triggers on a specific configuration: a virtual server that has both a BIG-IP APM access policy and an OAuth profile configured, running as an OAuth Authorization Server. Specially crafted traffic sent to such a virtual server can corrupt memory and lead to code execution on the data plane.

F5 is explicit that deployments using APM strictly as an OAuth Client or Resource Server — without an OAuth authorization server profile configured — are not affected. Appliance mode is in scope; this is a data-plane issue, not a control-plane one.


Exposure and Response

Shadowserver tracks more than 14,700 internet-exposed BIG-IP APM instances. CISA's advisory called this class of flaw "a frequent attack vector for malicious cyber actors" and warned of significant risk to federal networks specifically.

F5 has shared indicators of compromise and an iRule mitigation for organizations that can't patch immediately, available to customers with an active F5 Support contract. Watch for:

  • Multiple failed OAuth authentication attempts
  • Followed by suspicious commands
  • Followed shortly by a TMM SIGABRT crash

Mitigation

  1. Apply F5's patch immediately per advisory K000162605.
  2. If patching isn't immediately possible, deploy F5's iRule mitigation to allow for proactive forensic triage, then patch as soon as possible.
  3. Audit virtual server configurations for the combination of APM access policy + OAuth authorization server profile — this is the specific exposure condition.
  4. Review logs for the IoCs above, particularly TMM crash events following OAuth failures.
  5. Federal agencies: remediate per CISA's KEV deadline.

Broader Context

This is another entry in a difficult run for F5: the company disclosed a 2025 breach in which attackers stole undisclosed BIG-IP source code and vulnerability data, and BIG-IP products have repeatedly drawn attention from both state-backed and criminal threat actors since. Organizations running BIG-IP APM should treat configuration review and patching here as an urgent priority, not routine maintenance.


Sources

  • BleepingComputer — F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
  • SecurityWeek — Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
#F5#BIG-IP#Zero-Day#CVE-2026-94127#CISA KEV#OAuth

Related Articles

CVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

Heap-based buffer overflow in F5 BIG-IP APM (OAuth + access policy) allows unauthenticated RCE; added to CISA KEV as actively exploited.

7 min read

CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM

CISA has added CVE-2025-53521, a critical vulnerability in F5 BIG-IP Access Policy Manager, to its Known Exploited Vulnerabilities catalog after...

5 min read

CVE-2025-53521: F5 BIG-IP APM Remote Code Execution — CISA

A critical unauthenticated RCE vulnerability in F5 BIG-IP APM is being actively exploited in the wild. Malicious traffic targeting access policy virtual...

4 min read
Back to all News