MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-23 · via BleepingComputer

F5 issues emergency patch for BIG-IP APM zero-day under active exploitation

Image via BleepingComputer
Image via BleepingComputer

F5 has released patches for a critical zero-day vulnerability in its BIG-IP Access Policy Manager (APM) that is being actively exploited for remote code execution. The flaw, tracked as CVE-2026-94127, impacts deployments where APM is configured as an OAuth Authorization Server. F5 recommends customers check for signs of compromise and apply mitigations if immediate patching is not possible; CISA has also added the flaw to its known exploited vulnerabilities catalog.

Expanded Detail

The vulnerability specifically targets BIG-IP APM instances configured as OAuth Authorization Servers, while deployments using APM strictly as an OAuth Client or Resource Server remain unaffected. F5's advisory notes that administrators should watch for multiple OAuth authentication failures paired with suspicious commands followed by a TMM SIGABRT as potential indicators of compromise.

Shadowserver's tracking reveals more than 14,700 internet-exposed BIG-IP APM endpoints, though the number of vulnerable or already-patched systems remains unclear. This marks the eighth actively exploited F5 vulnerability flagged by CISA since November 2021, with four previously abused in ransomware campaigns. F5 itself disclosed a breach in October 2025 where state-sponsored hackers stole BIG-IP security source code.

Context

This vulnerability could have significant ripple effects given F5's customer base, which includes nearly half of the Fortune 50 companies. Organizations relying on BIG-IP APM for network access control may face urgent patching decisions, while those unable to apply fixes immediately must weigh mitigations against downtime. Active exploitation suggests attackers are moving quickly, and the CISA deadline for federal agencies could pressure broader adoption of patches. Smaller enterprises with limited security teams may be particularly exposed, lacking resources to detect subtle compromise indicators or implement the suggested iRule workaround promptly.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Check Point rushes hotfix for critical management server flaw under active exploitation · Cybersecurity
US agency flags three actively exploited Linux kernel vulnerabilities, including a 14-year-old bug · Cybersecurity
Critical Check Point bug grants unauthenticated root access to management servers · Cybersecurity
D-Link flags unpatched critical flaw in legacy routers with public exploit · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks.” Browse more stories.