Someone's attacking a critical 0-day RCE in F5 BIG-IP APM
Attackers are exploiting critical F5 BIG-IP APM zero-day CVE-2026-94127; CISA added it to KEV.
The Register reports F5 patched CVE-2026-94127, a heap-based buffer overflow in BIG-IP Access Policy Manager scored 9.3 on CVSS v4.0, affecting systems configured as an OAuth Authorization Server with an access policy and OAuth profile on the same virtual server. F5 and CISA say unknown attackers are exploiting it for remote code execution, and CISA gave federal agencies until Friday to patch. The article recalls a prior highly sophisticated intrusion in which attackers stole BIG-IP source code, undisclosed vulnerability details, and some customer configuration data. It also notes Mandiant previously linked exploitation of CVE-2023-46747 to UNC5174, assessed with moderate confidence as China-based.
- Heap overflow CVE-2026-94127 is scored CVSS 9.3 and is being exploited.
- CISA put it on KEV and gave federal agencies a Friday patch deadline.
- A prior F5 intrusion exposed source code and undisclosed flaw details.
- Mandiant linked older CVE-2023-46747 exploitation to China-nexus UNC5174.
Vulnerabilities mentionedAll →
- CVE-2023-467479.897%F5 BIG-IP TMUI Authentication Bypass Enables Unauthenticated RCEpublished · f5 BIG-IP Access Policy Manager KEV ransomware PoC ×2
Full article342 words · extracted from theregister.com · click to collapse
security
Good news: there's a patch. Bad news: both CISA and F5 warn that it's under active exploitation
F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code.
BIG-IP APM is a centralized access management and security proxy that allows users to connect to enterprise networks, applications, APIs, and cloud services via a single login.
The flaw, tracked as CVE-2026-94127, is a heap-based buffer overflow that affects BIG-IP APM systems configured as an OAuth Authorization Server, with an access policy and OAuth profile on the same virtual server. It received a critical 9.3 CVSS v4.0 score - so patch now.
REG AD
“We have learned that this vulnerability has been exploited,” F5 said in a Tuesday security advisory.
REG AD
F5 did not immediately respond to our questions, including how many systems have been compromised, and whether criminals are abusing the vulnerability to deploy ransomware.
Also on Tuesday, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, and gave federal agencies a Friday deadline to apply patches.
This warning comes about a year after F5 and CISA warned “highly sophisticated nation-state" hackers broke into the vendor’s network and stole BIG-IP source code, zero-day vulnerability details, and customer configuration data belonging to some users.
The attack posed an "imminent risk" to federal agencies, US cybersecurity officials said at the time. The US Justice Department allowed F5 to delay disclosing the intrusion after determining that delayed public disclosure was warranted. This only happens if public disclosure poses a substantial risk to national security or public safety.
Neither the feds nor private researchers have publicly attributed the intrusion to a particular group or country, but a year earlier Google's Mandiant threat hunters linked exploitation of the critical F5 BIG-IP flaw CVE-2023-46747 to UNC5174, an access broker it assessed with moderate confidence as operating from China. The group attempted to sell access to US defense contractor appliances and UK government entities.®