Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
How Sandboxing Closes the Phishing Detection Visibility Gap
September 23, 2026
Critical cPanel Vulnerability Exposes User Accounts
September 23, 2026
Outerlimit Raises $16M to Secure AI Agents with Zero Trust
September 23, 2026
Home/CyberSecurity News/Critical F5 BIG-IP Flaw Lets Attackers Run Remote Code, Patch Now
CyberSecurity News

Critical F5 BIG-IP Flaw Lets Attackers Run Remote Code, Patch Now

Key Takeaways A critical zero-day vulnerability (CVE-2026-94127) in F5 BIG-IP APM is under active exploitation. The flaw allows unauthenticated remote code execution on virtual servers configured...

Sarah simpson
Sarah simpson
September 23, 2026 3 Min Read
5 0

Key Takeaways

  • A critical zero-day vulnerability (CVE-2026-94127) in F5 BIG-IP APM is under active exploitation.
  • The flaw allows unauthenticated remote code execution on virtual servers configured with both an APM access policy and an OAuth profile acting as an Authorization Server.
  • With a CVSS v3.1 score of 9.8, the vulnerability demands immediate attention due to low attack complexity and severe potential impact.
  • F5 has released hotfixes, and temporary mitigations are available for affected deployments.

F5 BIG-IP Zero-Day Under Active Attack: Urgent Patching Required

F5 has issued a critical warning regarding a zero-day vulnerability in its BIG-IP Access Policy Manager (APM) deployments, which attackers are actively exploiting to achieve unauthenticated remote code execution. The flaw, identified as CVE-2026-94127, impacts specific configurations of BIG-IP virtual servers.

Table Of Content

  • Key Takeaways
  • F5 BIG-IP Zero-Day Under Active Attack: Urgent Patching Required
  • Vulnerability Details and Impact
  • Affected Configurations and Versions
  • Available Fixes and Mitigations
  • Detecting Exploitation
  • What You Should Do

Vulnerability Details and Impact

The vulnerability, a heap-based buffer overflow (CWE-122) with internal tracking ID 2524777, allows specially crafted network traffic to corrupt memory on the BIG-IP system, leading to arbitrary code execution. It has received a critical CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3, underscoring its severity. This high rating reflects the ease of exploitation, requiring no authentication, user interaction, or elevated privileges, and its potential to compromise confidentiality, integrity, and availability.

F5 published advisory K000162605 on September 22, 2026, after discovering that the issue was already being weaponized in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, emphasizing the immediate need for remediation.

Affected Configurations and Versions

Crucially, not all BIG-IP APM deployments are vulnerable. The flaw specifically targets virtual servers configured with both an APM access policy and an OAuth profile, where APM functions as an OAuth Authorization Server. Deployments using APM solely as an OAuth Client or Resource Server, without an OAuth authorization-server profile, are not affected. Appliance-mode systems, however, remain susceptible.

F5 clarified that the vulnerability resides within the data plane, which processes application traffic, and does not expose the control plane. Therefore, simply restricting access to the management interface is insufficient to prevent exploitation of an affected virtual server.

Affected BIG-IP APM releases include:

  • BIG-IP APM 21.1.0
  • Versions 17.5.0 through 17.5.1
  • Versions 17.1.0 through 17.1.3

F5 has evaluated other BIG-IP modules, BIG-IQ Centralized Management, BIG-IP Next, F5 Distributed Cloud services, NGINX products, F5OS variants, and F5 AI Gateway as unaffected. However, administrators should note that releases beyond their End of Technical Support are not evaluated, and their absence from the affected list should not be interpreted as an indication of safety.

Available Fixes and Mitigations

F5 has released engineering hotfixes to address the vulnerability:

  • Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso
  • Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso
  • Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso

Organizations unable to apply hotfixes immediately can contact F5 Support for a temporary iRule that mitigates attacks against the affected virtual server.

Detecting Exploitation

F5 advises defenders to proactively hunt for signs of exploitation. Key indicators include three specific events occurring in close temporal proximity:

  1. Repeated OAuth authentication failures.
  2. Suspicious command execution.
  3. A subsequent Traffic Management Microkernel (TMM) SIGABRT event.

Specifically, ten or more invalid-token messages in /var/log/apm, especially when originating from a single IP address, warrant investigation. Analysts can inspect failure counts using tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed and cross-reference timestamps with entries in /var/log/audit. While a TMM core file or an authentication failure alone does not confirm compromise, their frequency and temporal relationship are critical indicators.

Although F5 internally discovered the vulnerability, details regarding attacker identity, the scale of exploitation, or post-compromise objectives remain unconfirmed. This uncertainty underscores the importance of both immediate remediation and retrospective threat hunting.

What You Should Do

  • Inventory Assets: Identify all BIG-IP APM virtual servers, especially those configured with both an APM access policy and an OAuth profile acting as an Authorization Server.
  • Apply Hotfixes Immediately: Download and install the applicable engineering hotfixes for your BIG-IP APM versions without delay.
  • Implement Temporary Mitigations: If immediate patching is not feasible, contact F5 Support for the temporary iRule to protect affected virtual servers.
  • Threat Hunt: Review logs for indicators of compromise, specifically looking for repeated OAuth authentication failures, suspicious command execution, and TMM SIGABRT events occurring in close succession.
  • Preserve Logs: Ensure robust logging is enabled and logs are retained for forensic analysis in case of a suspected breach.
  • Prioritize Incident Response: Treat any confirmed exploitation as a high-priority incident, focusing on containing the threat and restoring affected systems.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitHackerPatchSecurityThreatVulnerabilityzero-day

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

WordPress Malware Hides in Plugin, Uses Blockchain for Covert C2

Next Post

New AI Malware Chooses Next Attack Steps, No Human Input Needed

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical AWS Lambda Flaw Bypasses IAM, Exposes Cloud Services
September 23, 2026
Critical Next.js CVE-2024-XXXXX RCE Flaw Lets Attackers Use SVG Files
September 23, 2026
New Malware Uses Evasive Domain Tactics to Hide Infrastructure
September 23, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us