BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 23, 2026 · 2 min read · Original story

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks.

BIG-IP APM (short for Access Policy Manager) is the company's centralized access management proxy solution that helps admins secure access to their organizations' networks, applications, cloud, and application programming interfaces (APIs).

Tracked as CVE-2026-94127, the flaw affects instances configured as an OAuth Authorization Server when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server.

"We have learned that this vulnerability has been exploited," F5 warned in a security advisory published on Tuesday. "Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability."

The company advised customers to review systems for indicators of compromise if they detect a combination of multiple OAuth authentication failures and suspicious commands, shortly followed by a TMM SIGABRT.

F5 also shared mitigation measures for admins who can't immediately install the security updates, which require applying an iRule (available from F5 Support) to the affected BIG-IP APM virtual server.

Internet threat monitoring non-profit Shadowserver currently tracks over 14,700 IP addresses with BIG-IP APM fingerprints. However, there is no information on how many have already been patched or are honeypots.

F5 BIG-IP APM exposed online (Shadowserver)

On Tuesday, the Cybersecurity and Infrastructure Security Agency (CISA) also added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered U.S. federal agencies to secure their networks against this flaw by Friday.

"These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise," the cybersecurity agency warned.

Cybercrime and state-backed threat groups have often exploited F5 vulnerabilities in recent years. For instance, attackers have targeted security flaws in F5 products to breach corporate networks, hijack devices, ​​​​​​map internal servers, deploy data-wiping malware, and steal sensitive documents.

F5 also disclosed in October 2025 that state-sponsored hackers breached its systems in August 2025 and stole undisclosed BIG-IP security source code and vulnerabilities.

Since November 2021, CISA has flagged eight actively exploited F5 vulnerabilities, four of which have also been abused in ransomware attacks.

F5 is a Fortune 500 company that provides cybersecurity, application delivery networking (ADN), and other services to more than 23,000 customers worldwide, including 48 of the Fortune 50 companies and 80% of the Fortune Global 500.

References in this story

  1. NVD - Home nvd.nist.gov
  2. myF5 my.f5.com
  3. myF5 my.f5.com
  4. myF5 my.f5.com
  5. Time series · IoT device statistics · The Shadowserver Foundation dashboard.shadowserver.org
  6. CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA www.cisa.gov
  7. Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…
  8. Iranian hackers are selling access to corporate networks www.bleepingcomputer.com An Iranian-backed hacker group has been observed while seeking to sell access to compromised corporate networks to other threat actors on underground forums and attempting to exploit F5 BIG-IP devices vulnerable to…
  9. New BIG-IP Next Central Manager bugs allow device takeover www.bleepingcomputer.com F5 has fixed two high-severity BIG-IP Next Central Manager vulnerabilities, which can be exploited to gain admin control and create rogue accounts on any managed assets.
  10. CISA: Hackers abuse F5 BIG-IP cookies to map internal servers www.bleepingcomputer.com CISA is warning that threat actors have been observed abusing unencrypted persistent F5 BIG-IP cookies to identify and target other internal devices on the targeted network.
  11. Fake F5 BIG-IP zero-day warning emails push data wipers www.bleepingcomputer.com The Israel National Cyber Directorate warns of phishing emails pretending to be F5 BIG-IP zero-day security updates that deploy Windows and Linux data wipers.
  12. Hackers use F5 BIG-IP malware to stealthily steal data for years www.bleepingcomputer.com A group of suspected Chinese cyberespionage actors named 'Velvet Ant' are deploying custom malware on F5 BIG-IP appliances to gain a persistent connection to the internal network and steal data.
  13. F5 says hackers stole undisclosed BIG-IP flaws, source code www.bleepingcomputer.com U.S. cybersecurity company F5 disclosed that nation-state hackers breached its systems and stole undisclosed BIG-IP security vulnerabilities and source code.
  14. Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…

Guides related to this story

← Back to all news