F5 BIG-IP Zero-Day Vulnerability Exploited – Critical Security Alert

www.news4hackers.com-f5-big-ip-zero-day-vulnerability-exploited-critical-security-alert-f5-big-ip-zero-day-vulnerability-exploited-critical-security-alert

Urgent warnings issued after a critical vulnerability in F5 BIG-IP APM software is actively exploited by threat actors.

Critical Zero-Day Exploit Discovered in F5 BIG-IP APM Software

F5 and CISA issued urgent warnings to organizations following reports of active exploitation of a critical vulnerability in the BIG-IP Access Policy Manager (APM) component. The flaw, designated CVE-2026-94127 with a CVSS score of 9.8, enables unauthenticated attackers to execute arbitrary code on affected systems. The vulnerability arises when BIG-IP APM is configured as an OAuth Authorization Server, allowing malicious actors to trigger the flaw through crafted traffic directed at the appliance.

The flaw was identified internally by F5 and confirmed to be in use by threat actors. The company emphasized that the issue is confined to the data plane, with no exposure of the control plane.

Vulnerability Details

Affected versions include BIG-IP APM 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3. F5 has released hotfixes to address the vulnerability, while stating that other products are not impacted. CISA included CVE-2026-94127 in its Known Exploited Vulnerabilities (KEV) list, mandating federal agencies to apply patches within three days under BOD 26-04.

The advisory highlights three indicators of compromise (IoCs) that security teams should monitor. These artifacts, when observed together, signal potential exploitation attempts.

Configuration and Mitigation Guidance

F5 clarified that the vulnerability is not present in deployments where APM functions as an OAuth Client or Resource Server. Additionally, systems operating in Appliance mode are susceptible. The company urged users to review their configurations and apply updates promptly to mitigate risks.

The discovery underscores the growing threat landscape targeting identity and access management systems. Security teams are advised to monitor network traffic for signs of exploitation and validate patching efforts against the specified affected versions.



About Author

en_USEnglish