F5 BIG-IP APM Zero-Day Vulnerability Patched After RCE Exploit

www.news4hackers.com-f5-big-ip-apm-zero-day-vulnerability-patched-after-rce-exploit-f5-big-ip-apm-zero-day-vulnerability-patched-after-rce-exploit

A critical security vulnerability in F5’s BIG-IP APM solution has been actively exploited in remote code execution (RCE) attacks, prompting the company to issue urgent patches.

Vulnerability Details

The flaw, tracked as CVE-2026-94127, affects systems configured as OAuth Authorization Servers when specific access policies and OAuth profiles are deployed on a virtual server. This configuration creates a pathway for attackers to execute arbitrary code remotely, compromising the integrity of network and application access controls.

F5’s Response

F5 confirmed in a security advisory that the vulnerability is being leveraged in real-world attacks. The company clarified that deployments using BIG-IP APM solely as an OAuth Client or Resource Server—without Authorization Server profiles—remain unaffected.

Mitigation Steps

Administrators are urged to inspect systems for signs of compromise, including clusters of OAuth authentication failures followed by unexpected TMM SIGABRT events, which indicate potential exploitation. To mitigate the risk, F5 recommends applying an iRule provided through its support portal to affected virtual servers. This temporary measure aims to block exploitation attempts while organizations prepare for full patch implementation.

Shadowserver’s Findings

Meanwhile, the non-profit cybersecurity organization Shadowserver has identified over 14,700 IP addresses with BIG-IP APM fingerprints exposed online, though no data is available on the number of patched systems or honeypots within this dataset.

CISA’s Actions

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to address the flaw by a specified deadline. CISA emphasized that such vulnerabilities are frequently targeted by malicious actors, posing severe risks to organizational infrastructure.

Historical Context

Historically, threat groups—both cybercriminal and state-sponsored—have exploited F5 vulnerabilities to infiltrate networks, manipulate devices, map internal infrastructure, deploy destructive malware, and exfiltrate sensitive data. Since November 2021, CISA has documented eight actively exploited F5 flaws, four of which have been linked to ransomware campaigns.

F5’s Client Base

F5, a Fortune 500 company serving over 23,000 clients globally, including 48 Fortune 50 enterprises and 80% of the Fortune Global 500, continues to face scrutiny over its security posture.

Recommendations

Organizations utilizing BIG-IP APM are advised to prioritize patching, monitor for anomalous activity, and review configuration settings to eliminate exposure to the vulnerability.

Conclusion

The incident highlights the critical need for proactive vulnerability management in enterprise environments.



About Author

en_USEnglish