Skip to main content

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

0
Critical
Vulnerabilityremotercezero-day
Published: 09/23/2026 (09/23/2026, 07:34:18 UTC)
Source: SecurityWeek

Description

A critical remote code execution vulnerability (CVE-2026-94127) affects F5 BIG-IP Access Policy Manager (APM) when configured as an OAuth Authorization Server. Unauthenticated attackers can exploit this zero-day flaw by sending malicious traffic to vulnerable BIG-IP appliances. The vulnerability impacts specific versions of BIG-IP APM and has been actively exploited in the wild. F5 has released hotfixes addressing the issue, and CISA has added it to its Known Exploited Vulnerabilities list, urging rapid patching.

Affected software

Affected versions
>=21.1.0 <=21.1.0>=17.5.0 <=17.5.1>=17.1.0 <=17.1.3

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 07:47:54 UTC

Technical Analysis

CVE-2026-94127 is a critical-severity vulnerability in F5 BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution. The flaw is exploitable only when BIG-IP APM is configured as an OAuth Authorization Server on a virtual server with an OAuth profile. The vulnerability affects BIG-IP APM versions 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3. F5 discovered the issue internally and confirmed active exploitation. The vulnerability is a data plane issue affecting appliance mode, with no control plane exposure. F5 has released hotfixes to remediate the vulnerability and published indicators of compromise to aid detection. CISA has mandated patching within three days for federal agencies.

Potential Impact

The vulnerability enables unauthenticated attackers to achieve remote code execution on vulnerable BIG-IP APM deployments configured as OAuth Authorization Servers. This can lead to full compromise of the affected appliance, potentially allowing attackers to execute arbitrary code remotely. The issue is actively exploited in the wild, increasing the urgency of remediation. The vulnerability does not affect BIG-IP APM deployments configured as OAuth Clients or Resource Servers, nor other F5 products.

Mitigation Recommendations

F5 has released official hotfixes for the affected BIG-IP APM versions (21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3). Organizations should apply these hotfixes immediately to mitigate the risk. CISA has added this vulnerability to its Known Exploited Vulnerabilities list and mandates patching within three days for federal agencies. Monitoring for the published indicators of compromise is recommended to detect potential exploitation. No other mitigation steps are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.65,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/critical-f5-big-ip-vulnerability-exploited-as-zero-day/","fetched":true,"fetchedAt":"2026-09-23T07:47:47.244Z","wordCount":889}

Threat ID: 6ab38423f7a7c5410676f91e

Added to database: 09/23/2026, 07:47:47 UTC

Last enriched: 09/23/2026, 07:47:54 UTC

Last updated: 09/23/2026, 08:42:48 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses