Advertisement

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

Summary: Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution.

F5 and the U.S. Cybersecurity and Infrastructure Security Agency have warned organizations to urgently patch a critical BIG-IP vulnerability that attackers were exploiting as a zero-day before a fix became available.

Tracked as CVE-2026-94127, the vulnerability affects F5’s BIG-IP Access Policy Manager (APM) and carries a CVSS severity score of 9.8. Successful exploitation can allow an unauthenticated attacker to achieve remote code execution on vulnerable systems.

The vulnerability is particularly important because BIG-IP appliances are commonly positioned at critical points in enterprise networks, where they can handle authentication and access to internal applications.

Advertisement
Attackers Can Exploit the Flaw Remotely

According to F5, CVE-2026-94127 can be triggered by sending malicious network traffic to a vulnerable BIG-IP appliance.

However, exploitation requires a specific configuration: a BIG-IP APM access policy and an OAuth profile must be configured on a virtual server, with APM operating as an OAuth Authorization Server. Deployments where APM functions only as an OAuth Client or Resource Server are not affected by this particular vulnerability.

The flaw does not require an attacker to authenticate before attempting exploitation.

That combination — network accessibility, no authentication requirement and the possibility of remote code execution — explains the vulnerability’s critical severity rating.

F5 also confirmed that systems configured in Appliance mode remain vulnerable.

The company described CVE-2026-94127 as a data-plane issue and said there is no associated control-plane exposure.

Exploitation Was Already Happening

The vulnerability was discovered internally by F5, but the company subsequently determined that attackers had already been exploiting it.

F5 has not disclosed who was behind the attacks, how long exploitation had been occurring or which organizations were targeted.

The lack of those details makes it difficult to determine the full scale of the campaign, but the confirmation of exploitation changes the vulnerability from a theoretical security risk into an active incident-response concern.

Organizations operating affected BIG-IP systems therefore need to consider not only whether they are vulnerable, but also whether their appliances may have already been compromised.

F5 published three indicators of compromise that administrators can use during investigations. The company cautioned that the indicators should be correlated together, particularly when they appear frequently, rather than treating a single occurrence as definitive proof of compromise.

Several BIG-IP APM Versions Are Vulnerable

F5 identified multiple affected BIG-IP APM releases, including:

  • BIG-IP APM 21.1.0
  • BIG-IP APM 17.5.0 through 17.5.1
  • BIG-IP APM 17.1.0 through 17.1.3

The company has released hotfixes addressing the vulnerability and says its other products are not affected by CVE-2026-94127.

Organizations should still verify their exact deployment configuration rather than relying exclusively on the installed version number. The vulnerability’s exploitability depends on the presence of the affected OAuth Authorization Server configuration.

Systems that meet both conditions — a vulnerable software version and the relevant APM configuration — should be treated as high-priority patching targets.

CISA Orders Rapid Remediation

CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog shortly after F5 published its advisory.

U.S. federal civilian agencies were instructed to remediate the vulnerability within three days, under the requirements of Binding Operational Directive 26-04.

Such a short remediation window reflects the combination of critical severity and confirmed exploitation.

Although the KEV requirement directly applies to U.S. federal civilian agencies, private organizations frequently use the catalog as a vulnerability-prioritization tool because inclusion confirms that exploitation has been observed in real attacks.

For enterprises using BIG-IP appliances, the issue deserves particular attention because these devices can occupy highly privileged positions between external users and sensitive internal services.

Edge Devices Remain Valuable Targets

CVE-2026-94127 is another example of attackers focusing on network appliances positioned at the edge of enterprise environments.

VPN gateways, firewalls, access-management platforms and application-delivery controllers are attractive because they are often internet-accessible while simultaneously maintaining trusted connections to internal infrastructure.

Compromising one of these systems can provide attackers with a valuable foothold without first compromising a conventional employee endpoint.

The situation is especially concerning when exploitation begins before defenders know a vulnerability exists. By the time a vendor releases a patch, attackers may already have established persistence or moved deeper into affected networks.

For that reason, applying F5’s hotfix should be accompanied by a review of the company’s published compromise indicators and other relevant appliance activity.

With unauthenticated remote code execution, a 9.8 CVSS score and confirmed zero-day exploitation, CVE-2026-94127 should be treated as an immediate remediation priority for organizations running affected BIG-IP APM configurations.

Advertisement

Key facts

  • A critical vulnerability in F5 BIG-IP devices is being exploited as a zero-day
  • Unauthenticated attackers can exploit the vulnerability
  • The exploit allows for remote code execution
  • Malicious traffic can be sent to BIG-IP devices to achieve compromise

Why it matters

This zero-day exploit targeting F5 BIG-IP devices, widely used for application delivery and security, poses a significant risk to internet infrastructure. Successful exploitation could allow attackers to gain control of critical network appliances, leading to widespread service disruptions, data breaches, and further compromise of connected systems.