F5 warns BIG-IP APM zero-day is under active attack

F5 has issued fixes for a critical BIG-IP Access Policy Manager vulnerability that the company says has already been exploited in the wild.

CVE-2026-94127 does not affect every BIG-IP APM installation, but it is serious for organizations using the affected configuration. Advisories and reporting available on September 25, 2026, indicate the vulnerable setup involves BIG-IP APM acting as an OAuth Authorization Server, with both an APM access policy and an OAuth profile on the same virtual server.

Deployments using APM strictly as an OAuth Client or OAuth Resource Server, without OAuth authorization server profiles configured, were reported by F5 as not affected. Software versions that have reached End of Technical Support were not evaluated by F5, so old branches should not be treated as cleared by omission.

Affected versions and hotfixes

BIG-IP APM branchAffected versionsFixed hotfix
21.121.1.0 before the engineering hotfixHotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.517.5.0 through 17.5.1 before the engineering hotfixHotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.117.1.0 through 17.1.3 before the engineering hotfixHotfix-BIGIP-17.1.3.5.0.41.14-ENG

The hotfix names should be checked against the current F5 advisory before production changes, since vendor engineering hotfix guidance can change.

Why the risk is high

CVE-2026-94127 is a remote code execution issue that does not require authentication. Rapid7 said exploitation requires network access to an affected virtual server rather than access to the BIG-IP management plane.

That detail affects remediation planning. Management interface restrictions remain good security hygiene, but they are not a fix for this vulnerability because the malicious traffic reaches the virtual server itself. Rapid7 and SecurityWeek also reported that BIG-IP systems in Appliance mode remain vulnerable because the issue is on the data plane, not the control plane.

The U.S. Cybersecurity and Infrastructure Security Agency also added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog on September 22, according to Rapid7, BleepingComputer, and SecurityWeek. BleepingComputer reported that federal civilian agencies were directed to secure affected systems by September 25.

The Canadian Cyber Centre recommends identifying BIG-IP systems where an APM access policy and OAuth profile are configured on the same virtual server, applying the relevant vendor-supported hotfix, and using F5’s vendor-provided iRule through F5 Support if an immediate hotfix is not possible.

CERT-EU’s recommended order of operations is to preserve forensic evidence, apply the hotfix, check for signs of compromise, and start incident response if signs are found. That sequence matters because a patched system may still need investigation if it was exposed before the fix.

Compromise checks to prioritize

CERT-EU said administrators should treat a cluster of signals as suspicious when repeated OAuth authentication failures are followed by suspicious commands and a TMM SIGABRT shortly after.

  • APM logs: Review /var/log/apm for repeated failed UserInfo requests, especially 10 or more from a single IP address in a short window.
  • OAuth statistics: Check for unexplained growth in total_failed using tmctl global_oauth_stat -s total_requests,total_userinfo_requests,total_failed.
  • Audit logs: Review /var/log/audit around the same timestamps for suspicious commands.
  • TMM core files: Investigate core files in context. CERT-EU said a TMM core file alone is not an indicator, but it should be reviewed when paired with other signals.

Public reporting as of September 25, 2026, had not identified the attackers, target organizations, or a confirmed public proof-of-concept exploit. That uncertainty should keep response plans cautious rather than delayed.

Get new small business insights by email

Practical ideas and useful articles to help you make better business decisions.

HelperX Bot

Not sure what to read next?

I can suggest related Tech Help Canada articles based on the topic you’re reading now.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us

Leave a Comment

Tweet
Share
Share
Pin
WhatsApp
Reddit
Email