Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
F5 and CISA warned of an actively exploited critical zero-day (CVE-2026-94127) in BIG-IP APM enabling unauthenticated remote code execution.
F5 and CISA have warned that a critical zero-day vulnerability in F5 BIG-IP Access Policy Manager (APM) is being actively exploited. Tracked as CVE-2026-94127 with a CVSS score of 9.8, the flaw allows unauthenticated attackers to achieve remote code execution via malicious traffic when APM is configured as an OAuth Authorization Server. F5 has released hotfixes for affected versions, and CISA has added the CVE to its KEV list, mandating federal agencies patch within three days.
- F5 disclosed a critical zero-day vulnerability (CVE-2026-94127) in BIG-IP APM.
- The flaw allows unauthenticated remote code execution with a CVSS score of 9.8.
- CISA added the CVE to its Known Exploited Vulnerabilities (KEV) list.
- Exploitation requires a specific configuration: BIG-IP APM as an OAuth Authorization Server.
Vulnerabilities mentionedAll →
- CVE-2026-941279.32%Unauthenticated Heap-Overflow RCE in F5 BIG-IP APM with OAuth Profilepublished · F5 BIG-IP (Access Policy Manager) KEV PoC ×2
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article275 words · extracted from securityweek.com · click to collapse
F5 and CISA on Tuesday warned organizations that threat actors have been exploiting a critical-severity BIG-IP Access Policy Manager (APM) vulnerability as a zero-day.
The flaw is exploitable via malicious traffic sent to the appliance when “a BIG-IP APM access policy and an OAuth profile are configured on a virtual server,” F5 notes in its advisory.
Tracked as CVE-2026-94127 (CVSS score of 9.8), the bug allows unauthenticated attackers to achieve remote code execution (RCE) on a vulnerable deployment.
“We have learned that this vulnerability has been exploited,” F5 says, noting that it discovered the security defect internally.
According to the company, the issue can be triggered only when BIG-IP APM is configured as an OAuth Authorization Server, not on deployments using APM as an OAuth Client/Resource Server.
“The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure,” the company notes.
Advertisement. Scroll to continue reading.
BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 are vulnerable, and F5 has released hotfixes. No other products are vulnerable, the company says.
Additionally, the company published three indicators of compromise (IoCs), noting that their combined and frequent appearance should be correlated to an attack.
Just as F5 published its advisory, CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) list, urging federal agencies to patch it within three days, as mandated by BOD 26-04.
Related: Check Point Patches Exploited Management Server Zero-Day
Related: Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Related: Malicious B-tree NPM Package Accumulates Millions of Downloads
Related: AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/critical-f5-big-ip-vulnerability-exploited-as-zero-day/