F5 Reports Active Exploitation of BIG-IP Zero-Day Vulnerability
At a glance
- F5 published a security advisory on September 22, 2026.
- CVE-2026-94127 allows unauthenticated remote code execution.
- Hotfixes are available for affected BIG-IP APM versions.
F5 disclosed a critical security issue in its BIG-IP Access Policy Manager (APM) on September 22, 2026, after confirming that the vulnerability was being actively exploited in real-world attacks. The flaw impacts systems configured with both an OAuth profile and access policy on the same virtual server.
The vulnerability, tracked as CVE-2026-94127, is a heap-based buffer overflow that can enable unauthenticated attackers to execute code remotely on affected BIG-IP devices. F5 stated in its advisory that this issue represents a serious risk to organizations using the specified configurations.
Multiple cybersecurity authorities, including CERT-EU and the Canadian Centre for Cyber Security, published advisories on the same day as F5's announcement. These organizations confirmed the critical nature of the vulnerability and reported that exploitation had already been observed in the wild. Both agencies recommended immediate action to mitigate risk.
According to the Canadian Centre for Cyber Security, the vulnerability specifically affects BIG-IP APM versions 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0. The agency also detailed which hotfixes correspond to each affected version, urging administrators to apply them without delay.
What the numbers show
- The CVE-2026-94127 vulnerability has a CVSS v3.1 score of 9.8.
- CVSS v4.0 score for the flaw is 9.3.
- Advisories and alerts were published on September 22, 2026.
- Three main BIG-IP APM version branches are affected.
F5 made engineering hotfixes available for the impacted versions, including Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso. The Canadian Centre for Cyber Security specified which hotfix addresses each version branch, providing clear guidance for remediation.
CERT-EU advised organizations to preserve forensic evidence, apply the relevant hotfix, and review systems for signs of compromise. Indicators include OAuth authentication failures, suspicious command executions, and TMM SIGABRT events, according to the advisory.
Both CERT-EU and the Canadian Centre for Cyber Security recommended immediate application of the provided hotfixes and thorough forensic review of potentially affected systems. These steps are intended to limit the impact of ongoing exploitation and help organizations detect any unauthorized activity related to the vulnerability.
The coordinated publication of advisories by F5, CERT-EU, and the Canadian Centre for Cyber Security underscores the urgency of the situation. Organizations using BIG-IP APM with the vulnerable configuration are advised to act promptly to secure their systems and investigate for any signs of compromise.
* This article is based on publicly available information at the time of writing.