Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
A critical remote code execution vulnerability (CVE-2026-94127) affects F5 BIG-IP Access Policy Manager (APM) when configured as an OAuth Authorization Server. Unauthenticated attackers can exploit this zero-day flaw by sending malicious traffic to vulnerable BIG-IP appliances. The vulnerability impacts specific versions of BIG-IP APM and has been actively exploited in the wild. F5 has released hotfixes addressing the issue, and CISA has added it to its Known Exploited Vulnerabilities list, urging rapid patching.
AI Analysis
Technical Summary
CVE-2026-94127 is a critical-severity vulnerability in F5 BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution. The flaw is exploitable only when BIG-IP APM is configured as an OAuth Authorization Server on a virtual server with an OAuth profile. The vulnerability affects BIG-IP APM versions 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3. F5 discovered the issue internally and confirmed active exploitation. The vulnerability is a data plane issue affecting appliance mode, with no control plane exposure. F5 has released hotfixes to remediate the vulnerability and published indicators of compromise to aid detection. CISA has mandated patching within three days for federal agencies.
Potential Impact
The vulnerability enables unauthenticated attackers to achieve remote code execution on vulnerable BIG-IP APM deployments configured as OAuth Authorization Servers. This can lead to full compromise of the affected appliance, potentially allowing attackers to execute arbitrary code remotely. The issue is actively exploited in the wild, increasing the urgency of remediation. The vulnerability does not affect BIG-IP APM deployments configured as OAuth Clients or Resource Servers, nor other F5 products.
Mitigation Recommendations
F5 has released official hotfixes for the affected BIG-IP APM versions (21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3). Organizations should apply these hotfixes immediately to mitigate the risk. CISA has added this vulnerability to its Known Exploited Vulnerabilities list and mandates patching within three days for federal agencies. Monitoring for the published indicators of compromise is recommended to detect potential exploitation. No other mitigation steps are indicated by the vendor advisory.
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Description
A critical remote code execution vulnerability (CVE-2026-94127) affects F5 BIG-IP Access Policy Manager (APM) when configured as an OAuth Authorization Server. Unauthenticated attackers can exploit this zero-day flaw by sending malicious traffic to vulnerable BIG-IP appliances. The vulnerability impacts specific versions of BIG-IP APM and has been actively exploited in the wild. F5 has released hotfixes addressing the issue, and CISA has added it to its Known Exploited Vulnerabilities list, urging rapid patching.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-94127 is a critical-severity vulnerability in F5 BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution. The flaw is exploitable only when BIG-IP APM is configured as an OAuth Authorization Server on a virtual server with an OAuth profile. The vulnerability affects BIG-IP APM versions 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3. F5 discovered the issue internally and confirmed active exploitation. The vulnerability is a data plane issue affecting appliance mode, with no control plane exposure. F5 has released hotfixes to remediate the vulnerability and published indicators of compromise to aid detection. CISA has mandated patching within three days for federal agencies.
Potential Impact
The vulnerability enables unauthenticated attackers to achieve remote code execution on vulnerable BIG-IP APM deployments configured as OAuth Authorization Servers. This can lead to full compromise of the affected appliance, potentially allowing attackers to execute arbitrary code remotely. The issue is actively exploited in the wild, increasing the urgency of remediation. The vulnerability does not affect BIG-IP APM deployments configured as OAuth Clients or Resource Servers, nor other F5 products.
Mitigation Recommendations
F5 has released official hotfixes for the affected BIG-IP APM versions (21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3). Organizations should apply these hotfixes immediately to mitigate the risk. CISA has added this vulnerability to its Known Exploited Vulnerabilities list and mandates patching within three days for federal agencies. Monitoring for the published indicators of compromise is recommended to detect potential exploitation. No other mitigation steps are indicated by the vendor advisory.
Technical Details
- Classification
- {"confidence":0.65,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/critical-f5-big-ip-vulnerability-exploited-as-zero-day/","fetched":true,"fetchedAt":"2026-09-23T07:47:47.244Z","wordCount":889}
Threat ID: 6ab38423f7a7c5410676f91e
Added to database: 09/23/2026, 07:47:47 UTC
Last enriched: 09/23/2026, 07:47:54 UTC
Last updated: 09/23/2026, 08:42:48 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.