F5 Rushes Patch for Exploited BIG-IP APM Zero-Day Allowing Remote Code Execution
F5 releases security updates for a critical zero-day vulnerability in its BIG-IP Access Policy Manager (APM) that attackers are actively exploiting for remote code execution. The flaw, tracked as CVE-2026-94127, affects BIG-IP APM instances configured as an OAuth Authorization Server when an access policy and OAuth profile are set up on a virtual server. Deployments using APM only as an OAuth Client or Resource Server remain unaffected.
F5 confirms the vulnerability is under active exploitation and urges customers to patch immediately. Admins who cannot install updates right away can apply a mitigation iRule, available from F5 Support, on affected virtual servers. The company also advises checking for indicators of compromise, such as multiple OAuth authentication failures followed by suspicious commands and a TMM SIGABRT crash. Shadowserver currently tracks more than 14,700 internet-exposed IP addresses running BIG-IP APM, though it is unclear how many are patched or are honeypots.
The Cybersecurity and Infrastructure Security Agency (CISA) adds the flaw to its Known Exploited Vulnerabilities Catalog and orders U.S. federal agencies to secure their systems by Friday. Threat actors, including state-backed groups, have repeatedly targeted F5 products in recent years to breach networks, hijack devices, deploy wipers, and steal sensitive data. F5 also disclosed in 2025 that state-sponsored hackers stole BIG-IP security source code from its own systems.