MikhbarMIKHBAR
Cybersecurity

Critical F5 BIG-IP Zero-Day Vulnerability Exploited

F5 and CISA have issued warnings regarding an active zero-day exploit targeting a critical remote code execution vulnerability in F5 BIG-IP Access Policy Manager systems.

Critical F5 BIG-IP Zero-Day Vulnerability Exploited

Critical Zero-Day Flaw Discovered in F5 BIG-IP APM

F5 and CISA warned organizations on Tuesday that threat actors have been actively exploiting a critical-severity vulnerability in the F5 BIG-IP Access Policy Manager (APM) as a zero-day. According to F5 and its official advisory, the security defect can be triggered via malicious traffic sent to the appliance under specific configurations. Further details are available from SecurityWeek in the original source material.

Tracked under the identifier CVE-2026-94127, the vulnerability carries a maximum CVSS score of 9.8. It allows unauthenticated attackers to achieve remote code execution (RCE) on a vulnerable deployment, presenting severe security risks to enterprise networks utilizing the affected hardware and software configurations.

Specific Configuration Triggers and Technical Scope

F5 noted that it discovered the security defect internally. The flaw can be triggered only when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specifically when BIG-IP APM functions as an OAuth Authorization Server. Deployments utilizing APM strictly as an OAuth Client or Resource Server are not impacted by this trigger condition.

Furthermore, the company clarified that the BIG-IP system operating in Appliance mode remains vulnerable. F5 emphasized that this is strictly a data plane issue and that there is no control plane exposure associated with the vulnerability.

Impacted Software Versions and Released Hotfixes

The vulnerability impacts specific software iterations across multiple product branches. According to the manufacturer, BIG-IP APM versions 21.1.0, 17.5.0 through 17.5.1, and 17.1.0 through 17.1.3 are vulnerable.

To address the flaw, F5 has released targeted hotfixes for the affected deployments. The company confirmed that no other products outside of the specified BIG-IP APM ranges are vulnerable to this particular remote code execution defect.

Indicators of Compromise and CISA Mandate

Alongside the release of its software patches, the company published three indicators of compromise (IoCs). F5 noted that the combined and frequent appearance of these specific indicators should be carefully correlated by security teams to identify potential exploitation attempts.

Concurrently, the Cybersecurity and Infrastructure Security Agency moved swiftly following the disclosure. CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, urging federal civilian executive branch agencies to remediate and patch the vulnerability within a strict three-day timeframe as mandated by binding operational directive BOD 26-04.

Sources

  • SecurityWeekCritical F5 BIG-IP Vulnerability Exploited as Zero-Day