F5 fixes actively exploited zero-day flaw in BIG-IP APM

Summary

F5 has released patches for a critical remote code execution vulnerability (CVE-2026-94127) in its BIG-IP Access Policy Manager (APM) platform. This heap-based buffer overflow flaw impacts deployments configured as OAuth authorization servers and has already been actively exploited in the wild. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog.

IFF Assessment

FOE

The active exploitation of a critical vulnerability in widely used network infrastructure like F5 BIG-IP APM poses a significant risk to organizations, enabling potential unauthorized access and further attacks.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 25, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability allows for remote code execution, meaning attackers can potentially take full control of compromised F5 BIG-IP APM systems. Organizations using BIG-IP APM as an OAuth authorization server must prioritize applying the provided hotfixes or implementing the iRule mitigation immediately to prevent exploitation. Defenders should also actively monitor for indicators of compromise as suggested by F5.

Read Full Story →