F5 has released emergency updates for a critical zero-day vulnerability in BIG-IP Access Policy Manager (APM) that was actively exploited in remote code execution attacks before a patch was available.
Tracked as CVE-2026-94127, the flaw affects BIG-IP APM instances configured as an OAuth Authorization Server, specifically when an APM access policy and an OAuth profile are both applied to a virtual server. According to F5’s advisory, deployments using APM strictly as an OAuth Client or Resource Server, without OAuth authorization server profiles configured, are not affected.
“We have learned that this vulnerability has been exploited,” F5 said in its security notice. Unauthenticated attackers could send crafted traffic to vulnerable BIG-IP instances to gain remote code execution, according to reporting on the flaw.
Indicators of Compromise
F5 advised customers to check for signs of exploitation, particularly a combination of multiple OAuth authentication failures paired with suspicious commands, followed shortly by a TMM SIGABRT event. Organizations unable to apply the patch immediately can deploy a mitigating iRule, available through F5 Support, to the affected virtual server.
Wide Exposure
Threat monitoring nonprofit Shadowserver is currently tracking more than 14,700 internet-facing IP addresses with BIG-IP APM fingerprints. It is unclear how many of those systems remain unpatched or represent honeypots.
CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog and directed federal civilian agencies to remediate the issue by Friday, warning that these types of flaws are “a frequent attack vector for malicious cyber actors” and pose significant risk to federal networks.
A Recurring Target
F5 products have been a persistent target for both cybercriminal and state-sponsored groups in recent years, previously used to breach corporate networks, hijack devices, map internal infrastructure, deploy wiper malware, and exfiltrate sensitive documents. F5 also disclosed in October 2025 that state-sponsored attackers had breached its internal systems in August 2025 and stole undisclosed BIG-IP source code and vulnerability data.
Since November 2021, CISA has flagged eight actively exploited F5 vulnerabilities, four of which have also been leveraged in ransomware operations. F5 serves more than 23,000 customers globally, including 48 of the Fortune 50 and 80 percent of the Fortune Global 500, making prompt patching of this flaw a priority for enterprise security teams.
