F5 BIG-IP APM Zero-Day Exploited in Remote Code Execution Attacks
F5 has released a security update to address a critical BIG-IP Access Policy Manager (APM) zero-day vulnerability that is being exploited in remote code execution attacks.
F5 BIG-IP APM zero-day affects OAuth authorization servers
BIG-IP APM is F5’s centralized access management proxy solution. It enables administrators to securely access an organization’s networks, applications, cloud environments, and application programming interfaces (APIs).
Tracked as CVE-2026-94127, the vulnerability affects BIG-IP APM instances configured as OAuth authorization servers. BIG-IP APM access policies and OAuth profiles are configured on the virtual server.
“We have learned that this vulnerability has been exploited,” F5 said in a security advisory published Tuesday.
F5 said deployments that use APM strictly as the OAuth client or resource server, without an OAuth authentication server profile configured, are not affected by the vulnerability.
F5 urges customers to check for compromise
F5 advised customers to review their systems for signs of compromise. According to the company, a TMM SIGABRT occurs immediately after a combination of multiple OAuth authentication failures and a suspicious command is detected.
Administrators who cannot immediately install the security update can apply a mitigation using an iRule on the affected BIG-IP APM virtual server.
The nonprofit threat-monitoring organization Shadowserver is currently tracking more than 14,700 IP addresses with BIG-IP APM fingerprints. However, it is not known how many of these systems have already been patched or how many may be honeypots.

CISA adds CVE-2026-94127 to its Known Exploited Vulnerabilities catalog
On Tuesday, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to the Known Exploited Vulnerabilities (KEV) Catalog.
CISA directed U.S. federal agencies to protect their networks against the flaw by Friday.
“These types of vulnerabilities are a frequent attack vector for malicious cyber attackers and pose significant risks to federal enterprises,” CISA warned.
F5 vulnerabilities have been repeatedly exploited
F5 vulnerabilities have frequently been exploited by cybercriminals and state-sponsored threat groups in recent years. Attackers have used flaws in F5 products to penetrate corporate networks, hijack devices, map internal servers, deploy data-erasing malware, and steal sensitive documents.
F5 also disclosed in October 2025 that state-sponsored hackers had infiltrated its systems in August 2025 and stolen undisclosed BIG-IP security source code and vulnerabilities.
Since November 2021, CISA has reported eight actively exploited F5 vulnerabilities. Four of them have also been exploited in ransomware attacks.
F5 is a Fortune 500 company that provides cybersecurity, application delivery networking (ADN), and other services to more than 23,000 customers worldwide. Its customers include 48 of the Fortune 50 companies and 80% of the Fortune Global 500 companies.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



