F5 issues emergency patch for BIG-IP APM zero-day under active exploitation

F5 has released patches for a critical zero-day vulnerability in its BIG-IP Access Policy Manager (APM) that is being actively exploited for remote code execution. The flaw, tracked as CVE-2026-94127, impacts deployments where APM is configured as an OAuth Authorization Server. F5 recommends customers check for signs of compromise and apply mitigations if immediate patching is not possible; CISA has also added the flaw to its known exploited vulnerabilities catalog.
The vulnerability specifically targets BIG-IP APM instances configured as OAuth Authorization Servers, while deployments using APM strictly as an OAuth Client or Resource Server remain unaffected. F5's advisory notes that administrators should watch for multiple OAuth authentication failures paired with suspicious commands followed by a TMM SIGABRT as potential indicators of compromise.
Shadowserver's tracking reveals more than 14,700 internet-exposed BIG-IP APM endpoints, though the number of vulnerable or already-patched systems remains unclear. This marks the eighth actively exploited F5 vulnerability flagged by CISA since November 2021, with four previously abused in ransomware campaigns. F5 itself disclosed a breach in October 2025 where state-sponsored hackers stole BIG-IP security source code.
This vulnerability could have significant ripple effects given F5's customer base, which includes nearly half of the Fortune 50 companies. Organizations relying on BIG-IP APM for network access control may face urgent patching decisions, while those unable to apply fixes immediately must weigh mitigations against downtime. Active exploitation suggests attackers are moving quickly, and the CISA deadline for federal agencies could pressure broader adoption of patches. Smaller enterprises with limited security teams may be particularly exposed, lacking resources to detect subtle compromise indicators or implement the suggested iRule workaround promptly.