Critical F5 BIG-IP Flaw Lets Attackers Run Remote Code, Patch Now
Key Takeaways A critical zero-day vulnerability (CVE-2026-94127) in F5 BIG-IP APM is under active exploitation. The flaw allows unauthenticated remote code execution on virtual servers configured...
Key Takeaways
- A critical zero-day vulnerability (CVE-2026-94127) in F5 BIG-IP APM is under active exploitation.
- The flaw allows unauthenticated remote code execution on virtual servers configured with both an APM access policy and an OAuth profile acting as an Authorization Server.
- With a CVSS v3.1 score of 9.8, the vulnerability demands immediate attention due to low attack complexity and severe potential impact.
- F5 has released hotfixes, and temporary mitigations are available for affected deployments.
F5 BIG-IP Zero-Day Under Active Attack: Urgent Patching Required
F5 has issued a critical warning regarding a zero-day vulnerability in its BIG-IP Access Policy Manager (APM) deployments, which attackers are actively exploiting to achieve unauthenticated remote code execution. The flaw, identified as CVE-2026-94127, impacts specific configurations of BIG-IP virtual servers.
Table Of Content
Vulnerability Details and Impact
The vulnerability, a heap-based buffer overflow (CWE-122) with internal tracking ID 2524777, allows specially crafted network traffic to corrupt memory on the BIG-IP system, leading to arbitrary code execution. It has received a critical CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3, underscoring its severity. This high rating reflects the ease of exploitation, requiring no authentication, user interaction, or elevated privileges, and its potential to compromise confidentiality, integrity, and availability.
F5 published advisory K000162605 on September 22, 2026, after discovering that the issue was already being weaponized in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, emphasizing the immediate need for remediation.
Affected Configurations and Versions
Crucially, not all BIG-IP APM deployments are vulnerable. The flaw specifically targets virtual servers configured with both an APM access policy and an OAuth profile, where APM functions as an OAuth Authorization Server. Deployments using APM solely as an OAuth Client or Resource Server, without an OAuth authorization-server profile, are not affected. Appliance-mode systems, however, remain susceptible.
F5 clarified that the vulnerability resides within the data plane, which processes application traffic, and does not expose the control plane. Therefore, simply restricting access to the management interface is insufficient to prevent exploitation of an affected virtual server.
Affected BIG-IP APM releases include:
- BIG-IP APM 21.1.0
- Versions 17.5.0 through 17.5.1
- Versions 17.1.0 through 17.1.3
F5 has evaluated other BIG-IP modules, BIG-IQ Centralized Management, BIG-IP Next, F5 Distributed Cloud services, NGINX products, F5OS variants, and F5 AI Gateway as unaffected. However, administrators should note that releases beyond their End of Technical Support are not evaluated, and their absence from the affected list should not be interpreted as an indication of safety.
Available Fixes and Mitigations
F5 has released engineering hotfixes to address the vulnerability:
- Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso
- Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso
- Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso
Organizations unable to apply hotfixes immediately can contact F5 Support for a temporary iRule that mitigates attacks against the affected virtual server.
Detecting Exploitation
F5 advises defenders to proactively hunt for signs of exploitation. Key indicators include three specific events occurring in close temporal proximity:
- Repeated OAuth authentication failures.
- Suspicious command execution.
- A subsequent Traffic Management Microkernel (TMM) SIGABRT event.
Specifically, ten or more invalid-token messages in /var/log/apm, especially when originating from a single IP address, warrant investigation. Analysts can inspect failure counts using tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed and cross-reference timestamps with entries in /var/log/audit. While a TMM core file or an authentication failure alone does not confirm compromise, their frequency and temporal relationship are critical indicators.
Although F5 internally discovered the vulnerability, details regarding attacker identity, the scale of exploitation, or post-compromise objectives remain unconfirmed. This uncertainty underscores the importance of both immediate remediation and retrospective threat hunting.
What You Should Do
- Inventory Assets: Identify all BIG-IP APM virtual servers, especially those configured with both an APM access policy and an OAuth profile acting as an Authorization Server.
- Apply Hotfixes Immediately: Download and install the applicable engineering hotfixes for your BIG-IP APM versions without delay.
- Implement Temporary Mitigations: If immediate patching is not feasible, contact F5 Support for the temporary iRule to protect affected virtual servers.
- Threat Hunt: Review logs for indicators of compromise, specifically looking for repeated OAuth authentication failures, suspicious command execution, and TMM SIGABRT events occurring in close succession.
- Preserve Logs: Ensure robust logging is enabled and logs are retained for forensic analysis in case of a suspected breach.
- Prioritize Incident Response: Treat any confirmed exploitation as a high-priority incident, focusing on containing the threat and restoring affected systems.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.