Someone's attacking a critical 0-day RCE in F5 BIG-IP APM
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Vendors and products
- F5
- Industries
- Government
- Reported by
- 1 outlet
security
Good news: there's a patch. Bad news: both CISA and F5 warn that it's under active exploitation
F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code.
BIG-IP APM is a centralized access management and security proxy that allows users to connect to enterprise networks, applications, APIs, and cloud services via a single login.
The flaw, tracked as CVE-2026-94127, is a heap-based buffer overflow that affects BIG-IP APM systems configured as an OAuth Authorization Server, with an access policy and OAuth profile on the same virtual server. It received a critical 9.3 CVSS v4.0 score - so patch now.
“We have learned that this vulnerability has been exploited,” F5 said in a Tuesday security advisory.
F5 did not immediately respond to our questions, including how many systems have been compromised, and whether criminals are abusing the vulnerability to deploy ransomware.
Also on Tuesday, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, and gave federal agencies a Friday deadline to apply patches.
This warning comes about a year after F5 and CISA warned “highly sophisticated nation-state" hackers broke into the vendor’s network and stole BIG-IP source code, zero-day vulnerability details, and customer configuration data belonging to some users.
The attack posed an "imminent risk" to federal agencies, US cybersecurity officials said at the time. The US Justice Department allowed F5 to delay disclosing the intrusion after determining that delayed public disclosure was warranted. This only happens if public disclosure poses a substantial risk to national security or public safety.
Neither the feds nor private researchers have publicly attributed the intrusion to a particular group or country, but a year earlier Google's Mandiant threat hunters linked exploitation of the critical F5 BIG-IP flaw CVE-2023-46747 to UNC5174, an access broker it assessed with moderate confidence as operating from China. The group attempted to sell access to US defense contractor appliances and UK government entities.®
Reproduced in full under licence from The Register. © The Register.
Coverage
One outlet has carried this so far.
2026-09-23 18:09 UTC
Related stories
- Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
BleepingComputer · 2026-09-23 · exploited
- Hackers start exploiting critical WordPress flaw for code execution
BleepingComputer · 2026-09-23
- A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
The Hacker News · 2026-09-23
- Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
BleepingComputer · 2026-09-23
- MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
The Hacker News · 2026-09-23 · exploited