F5 patches actively exploited BIG-IP zero-day, CISA gives federal agencies until Friday

F5 released emergency security updates Tuesday for a critical zero-day vulnerability in BIG-IP Access Policy Manager (APM) that attackers are actively exploiting to achieve remote code execution. The flaw, tracked as CVE-2026-94127, affects BIG-IP APM instances configured as an OAuth Authorization Server, where an access policy and OAuth profile are set up on the same virtual server. Deployments using APM strictly as an OAuth client or resource server are not affected.
The vulnerability matters immediately because of who relies on the product: F5 is a Fortune 500 company serving more than 23,000 customers, including 48 of the Fortune 50, and BIG-IP APM sits at the center of how many large organizations manage access to their networks, applications, and APIs. The Cybersecurity and Infrastructure Security Agency added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog the same day F5 published its advisory, and ordered federal agencies to secure their networks against the flaw by Friday — an unusually tight turnaround that signals how seriously CISA is treating active exploitation.
"We have learned that this vulnerability has been exploited," F5 said in its advisory. The company published indicators of compromise for administrators to check, describing a pattern of multiple OAuth authentication failures followed by suspicious commands and a TMM (Traffic Management Microkernel) SIGABRT crash. For organizations that cannot immediately deploy the patch, F5 published a mitigation iRule that can be applied to the affected virtual server as a stopgap.
The scale of potential exposure is significant. Internet threat monitoring nonprofit Shadowserver currently tracks more than 14,700 IP addresses with BIG-IP APM fingerprints online, though it's unclear how many are already patched, misconfigured in a way that avoids the vulnerable OAuth configuration, or honeypots designed to attract attackers.
This is not F5's first brush with serious security trouble. In October 2025, the company disclosed that state-sponsored hackers had breached its internal systems in August 2025 and stolen undisclosed BIG-IP source code and vulnerability details — raising the possibility that some subsequently discovered flaws, including this one, trace back to that stolen research. CISA has flagged eight actively exploited F5 vulnerabilities since November 2021, four of which were also used in ransomware attacks. Attackers have previously used F5 flaws to breach corporate networks, hijack devices, map internal infrastructure, and deploy data-wiping malware.
Organizations running BIG-IP APM with OAuth authorization server profiles configured should apply F5's patch immediately or deploy the mitigation iRule, and review logs for the indicators of compromise F5 published, regardless of the Friday federal deadline.
Originally reported by BleepingComputer. Read the original article for additional details.
View original source