F5 has released security updates for a critical BIG-IP APM zero-day vulnerability exploited in remote code execution attacks, BleepingComputer reports.
Tracked as CVE-2026-94127, the flaw affects systems configured as an OAuth Authorization Server when a BIG-IP APM access policy and OAuth profile are configured on a virtual server. F5 said it had learned that the vulnerability was being exploited.
Deployments using APM only as an OAuth Client / Resource Server, without OAuth authorization server profiles, are not affected, according to F5.
F5 advised customers to check for indicators of compromise if multiple OAuth authentication failures and suspicious commands are followed shortly by a TMM SIGABRT. The company also provided an iRule mitigation through F5 Support for systems that cannot be updated immediately.
Shadowserver tracks more than 14,700 IP addresses with BIG-IP APM fingerprints, but it is unclear how many have been patched or are honeypots.
CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered U.S. federal agencies to secure their networks by Friday.
Since November 2021, CISA has flagged 8 actively exploited F5 vulnerabilities; 4 were also abused in ransomware attacks. F5 disclosed in October 2025 that state-sponsored hackers breached its systems in August 2025 and stole undisclosed BIG-IP security source code and vulnerabilities.
F5 says it serves more than 23,000 customers worldwide, including 48 of the Fortune 50 companies and 80% of the Fortune Global 500.
Comments
0No comments yet. Be the first to comment.