Particle.news
Download on the App Store

Critical F5 BIG-IP APM Zero-Day Allows Unauthenticated Remote Code Execution

Exploitation can give attackers a deep network foothold, prompting CISA to order federal agencies to remediate by Sept 25, 2026.

Overview

  • F5 disclosed the heap-based buffer overflow tracked as CVE-2026-94127 on Sept. 22 and said it has seen the flaw exploited in the wild.
  • The bug only affects BIG-IP Access Policy Manager when it is configured as an OAuth Authorization Server with an APM access policy and an OAuth authorization-server profile on the same virtual server.
  • F5 released engineering hotfixes for affected 21.1, 17.5, and 17.1 branches and published an iRule mitigation that customers can apply when they cannot install the hotfix immediately.
  • F5 and CERT-EU published indicators of compromise to guide triage, including repeated OAuth failures, suspicious commands in audit logs, and TMM SIGABRT events that should trigger incident response.
  • Internet exposure is significant with Shadowserver fingerprinting over 14,700 BIG-IP APM addresses and prior theft of BIG-IP source code in 2025 increases concern about weaponization and deeper intrusions for breached organizations.