Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
A critical zero-day vulnerability in F5 BIG-IP Access Policy Manager (APM) has been actively exploited by threat actors. The flaw allows unauthenticated remote code execution, and F5 has released hotfixes to address the issue, urging organizations to patch immediately.
F5 and the Cybersecurity and Infrastructure Security Agency (CISA) issued a warning on Tuesday regarding a critical zero-day vulnerability within the F5 BIG-IP Access Policy Manager (APM). The vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), stems from a configuration issue where malicious traffic can be directed to the appliance when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server. F5 discovered the security defect internally and has confirmed that threat actors are actively exploiting it. The vulnerability is only triggered when BIG-IP APM is configured as an OAuth Authorization Server, not when used as an OAuth Client/Resource Server, and also affects BIG-IP APM in Appliance mode. F5 has released hotfixes for vulnerable versions, including 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3. The company has also published three indicators of compromise (IoCs) to aid in detection and correlation. CISA has added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) list, mandating patching for federal agencies within three days, as per BOD 26-04.