Security

F5 patches an actively exploited APM zero day as CISA orders federal fix by September 25

A heap-based buffer overflow in F5's BIG-IP access manager is already being used to run code on unpatched systems, and federal agencies have until September 25 to fix it.

T
By TechQuire Daily Staff TechQuire Daily Staff
September 24, 2026 / 7 min read

F5 sells BIG-IP Access Policy Manager (APM) as the module that controls how users reach an organization's applications and networks. The product is a centralized access management proxy that secures access to networks, applications, cloud services and APIs, and it is commonly deployed at the edge of corporate networks where it brokers authentication and authorization for internal systems. That position makes it both valuable and exposed. F5 is a Fortune 500 company serving more than 23,000 customers, including 48 of the Fortune 50 companies and 80 percent of the Fortune Global 500, so a flaw in a single edge module can have consequences well beyond one network.

One of the more sensitive ways to run APM is as an OAuth Authorization Server. In that configuration the appliance issues access tokens to applications, which means it holds a trust position that attackers would like to occupy. When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, the device exposes an authentication surface that is reachable from the network, and that is exactly the configuration at the center of the newest F5 security emergency. Deployments that use APM strictly as an OAuth Client or Resource Server, without OAuth authorization server profiles configured, are not affected.

That distinction matters because it narrows the population of exposed systems while concentrating risk. The vulnerable setup is not an exotic one: organizations that centralized single sign-on and token issuance on BIG-IP often run exactly this combination. F5 said it discovered the defect internally, and it published its advisory on Tuesday, September 22, 2026, alongside engineering hotfixes for the affected branches.

By the end of that same day, the United States federal government had already placed the flaw on its list of vulnerabilities that must be treated as an emergency. The result is a three day remediation clock for federal civilian agencies and a scramble for everyone else.

Key Facts

The vulnerability is tracked as CVE-2026-94127, a heap-based buffer overflow in BIG-IP APM. F5 rated it 9.8 out of 10 on CVSS v3.1 and 9.3 on CVSS v4.0. Exploitation allows an unauthenticated attacker to perform remote code execution (RCE) on a vulnerable deployment, according to the company. SecurityWeek reported on September 22 that F5 and CISA warned organizations that threat actors had been exploiting the critical-severity flaw as a zero-day, and that the bug is reachable via malicious traffic sent to the appliance when a BIG-IP APM access policy and an OAuth profile are configured on a virtual server.

F5's advisory, published as K000162605 on Tuesday, is blunt about the state of play. "We have learned that this vulnerability has been exploited," the company wrote. The advisory also specifies that "the BIG-IP system in Appliance mode is also vulnerable" and that "this is a data plane issue; there is no control plane exposure." Because the malicious traffic goes to the virtual server itself, restricting access to the BIG-IP management interface does not protect against this flaw.

Affected versions and their hotfixes are specific. Branch 21.1 (21.1.0) is fixed in Hotfix-BIGIP-21.1.0.2.0.30.22-ENG; branch 17.5 (17.5.0 to 17.5.1) in Hotfix-BIGIP-17.5.1.9.0.160.12-ENG; and branch 17.1 (17.1.0 to 17.1.3) in Hotfix-BIGIP-17.1.3.5.0.41.14-ENG. F5 said no other products are vulnerable.

CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) Catalog on September 22 and gave federal civilian agencies until September 25, 2026 to apply F5's mitigations. The Hacker News reported on September 23 that CISA told agencies to apply the iRule mitigation first "to allow for proactive forensic triage," and then to "install the final vendor patch as soon as possible." Admins who cannot patch immediately can request the iRule from F5 support and apply it to the affected virtual server.

Exposure is broad. BleepingComputer reported on September 22 that Shadowserver currently tracks over 14,700 IP addresses with BIG-IP APM fingerprints, although it is unknown how many of those are patched or are honeypots. CISA added three other actively exploited flaws to the KEV Catalog the same day: CVE-2026-85102 and CVE-2026-93616 in Check Point multiple products, and CVE-2026-93952 in Arista VeloCloud Orchestrator. Since November 2021, CISA has flagged eight actively exploited F5 vulnerabilities, four of which were abused in ransomware attacks.

Analysis

What this really means is that the window between disclosure and mass exploitation has effectively closed for edge authentication appliances. F5 did not learn about CVE-2026-94127 from a researcher's report; the company discovered it internally and then learned that it had already been exploited, which means the attacker activity predates the patch. Security Affairs reported on September 23 that F5 confirmed exploitation had already been observed at the moment of disclosure. A CVSS score of 9.8 combined with pre-patch exploitation and an unauthenticated network path is about as severe as enterprise vulnerability management gets.

The mitigating factors are real but narrow. Only deployments acting as an OAuth Authorization Server are exposed, and F5 says its own engineering hotfixes are available for all three affected branches, plus an iRule workaround for organizations that need time. CISA's sequencing advice, apply the iRule for forensic triage and then install the vendor patch, shows the agency expects defenders to hunt for evidence before they destroy it. That is a sensible instruction, but it also assumes an organization has the logging and staff to run a hunt on short notice.

The bigger picture here is that identity infrastructure has become the preferred target. BIG-IP APM issues tokens; a compromise there can translate into trusted access to applications across an enterprise, and the indicators F5 published point at that intersection: repeated OAuth authentication failures followed by suspicious commands and, shortly afterward, a TMM SIGABRT. The Hacker News reported on September 23 that defenders should look for 10 or more failed UserInfo requests from a single IP in the /var/log/apm log, plus a TMM SIGABRT. Attackers who understand that a SIGABRT is easy to dismiss as a crash have an advantage over teams that treat appliance restarts as routine noise.

Aggregate data supports the pattern of persistence. Eight actively exploited F5 vulnerabilities since November 2021, with four abused in ransomware, is a track record that suggests edge appliances are not being patched at the cadence attackers require. CERT-EU's guidance, preserve forensic evidence first, apply the hotfix, check for signs of compromise, and start incident response if any are found, is the right order of operations for an appliance that may already be hosting an intruder.

Why It Matters

The three day federal deadline under Binding Operational Directive (BOD) 26-04 is the clearest signal of how seriously the government is treating this. BOD 26-04, Prioritizing Security Updates Based on Risk, establishes vulnerability management requirements for Federal Civilian Executive Branch agencies and requires rapid remediation of high-risk vulnerabilities listed in the KEV Catalog, particularly those on publicly exposed assets that grant total control after exploitation. CISA said on September 22 that "these types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise." While the directive binds only federal civilian agencies, CISA encourages all organizations to adopt risk-based vulnerability management.

The private sector math is harsher. Shadowserver's count of more than 14,700 tracked IP addresses with BIG-IP APM fingerprints is a lower bound on internet exposure and says nothing about patch state. With more than 23,000 F5 customers, including 48 of the Fortune 50 and 80 percent of the Fortune Global 500, a single overlooked OAuth Authorization Server can become an entry point into a very large network. The iRule is a bridge, not a destination, and every day it stays in place is a day the final patch is still pending.

There is also a detection problem. A data plane bug that leaves a SIGABRT in its wake can look like instability rather than intrusion, and the OAuth failure patterns F5 describes can be buried in high-volume authentication logs. Organizations that run APM as an authorization server should be treating the published indicators as a search query right now, not as a document to file.

Next Up

The immediate task is mechanical: inventory BIG-IP APM deployments, determine which ones function as OAuth Authorization Servers, and apply the matching hotfix from branch 21.1, 17.5 or 17.1. Where patching cannot happen at once, the F5 support iRule belongs on the affected virtual server, and logs should be reviewed for the indicators F5 and CISA described. Federal agencies face the September 25 deadline; everyone else should assume the same clock.

The longer term question is whether F5's edge portfolio can keep absorbing this kind of attention. Eight actively exploited vulnerabilities since November 2021 is not a one-off, and each disclosure cycle restarts the same race between administrators and attackers. Until that pattern changes, the safest assumption for any organization running BIG-IP APM as an OAuth Authorization Server is that the appliance is a target, and that a crash log is never just a crash log.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.