F5 Releases Urgent Patches for Actively Exploited BIG-IP Zero-Day Vulnerability

F5 rates CVE-2026-94127 as highly severe, with a CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3; the vulnerability is also tracked internally as 2524777 and classified as Critical.
F5 said administrators should investigate for a possible compromise when they observe multiple OAuth authentication failures followed by suspicious commands and, shortly afterward, a TMM SIGABRT.
Shadowserver was tracking more than 14,700 IP addresses with BIG-IP APM fingerprints, although it could not determine how many of those systems had been patched or represented honeypots.
Successful exploitation could allow an attacker to install software, access or alter data, delete information, or create highly privileged accounts, depending on the privileges available to the compromised environment.
F5’s assessment found that several related products and platforms—including BIG-IQ Centralized Management, BIG-IP Next, F5 Distributed Cloud services, NGINX products, F5OS variants, and F5 AI Gateway—were not affected; however, releases beyond End of Technical Support were not evaluated and should not be presumed safe merely because they are absent from the affected-release list.
F5 has released emergency patches for a critical zero-day vulnerability in BIG-IP Access Policy Manager that attackers are actively exploiting to run malicious code without any authentication. Scworld reports the flaw, tracked as CVE-2026-94127, carries a CVSS severity score of 9.8 and affects virtual servers that combine an APM access policy with an OAuth profile configured as an Authorization Server.
CISA has already added the vulnerability to its Known Exploited Vulnerabilities catalog, signaling widespread concern across the cybersecurity community. Organizations with exposed BIG-IP APM systems must treat this as an urgent priority—the flaw lives in the data plane, so blocking access to the management interface alone will not stop attacks.
Dev.to explains the vulnerability is a heap-based buffer overflow residing in BIG-IP APM when it operates as an OAuth Authorization Server. Administrators who use APM only as an OAuth Client or Resource Server are not at risk. The flaw allows unauthenticated attackers to trigger arbitrary code execution by sending specially crafted requests to exposed virtual servers.
F5 assigned the vulnerability an internal tracking number of 2524777 and classified it as Critical. The CVSS v4.0 score of 9.3 confirms the severity even by newer rating standards. Appliance-mode systems running BIG-IP APM are also vulnerable, with no configuration exemptions outside of the OAuth Authorization Server requirement.
F5 identified a telltale pattern of exploitation: multiple failed OAuth authentication attempts followed by suspicious commands, culminating in a TMM SIGABRT—a sudden crash of the Traffic Management Module. Administrators should hunt their logs for this sequence immediately to determine if their systems have been breached. A successful attack could let an intruder install software, steal data, alter configurations, or create privileged backdoor accounts.
Network World notes that Shadowserver tracked over 14,700 IP addresses hosting BIG-IP APM fingerprints on the public internet, though the exact number of patched or honeypot systems remains unknown. This large exposed surface means attackers have many potential targets—and patch adoption will likely lag, leaving windows of vulnerability open.
F5 released hotfixes for affected BIG-IP APM versions and provided interim mitigation guidance for organizations unable to patch immediately. UK Head Topics urges administrators to prioritize installation, then investigate systems for signs of compromise and apply available fixes as soon as possible. Delaying remediation risks active exploitation by known threat actors.
F5 confirmed that other products—including BIG-IQ Centralized Management, BIG-IP Next, F5 Distributed Cloud, NGINX, F5OS, and F5 AI Gateway—are not vulnerable. However, software versions beyond End of Technical Support were not evaluated and should not be assumed safe simply because they don't appear on the affected-release list. Verify your exact configuration and version before concluding you are protected.
Publishers
17
Articles
7
Reach
24