Skip to content
feed: live
>_0dayNews
f5
● Breaking

F5 Patches BIG-IP APM RCE Zero-Day Under Attack

CVSS 9.8 F5 BIG-IP APM heap overflow: unauth RCE when an access policy and OAuth profile share a virtual server. Confirmed exploited; patches available.

F5 Patches BIG-IP APM RCE Zero-Day Under Attack
Photo: Justin Hobson (Justin1569 at English Wikipedia) / Wikimedia Commons · CC BY-SA 3.0
kilobaudDave "Kilobaud" Ferris·Published ·2 min read

F5 has shipped patches for a critical heap-based buffer overflow in BIG-IP APM, tracked as CVE-2026-94127, a CVSS 9.8 flaw that lets an unauthenticated attacker achieve remote code execution on affected appliances. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 22, confirming active exploitation in the wild. Federal agencies under BOD 26-04 have until September 25 to remediate.

Three days on a network-edge appliance. That is the window.

The vulnerability

The flaw lives in BIG-IP APM and triggers when an access policy and an OAuth profile are both configured on the same virtual server. For deployments matching that profile, the heap overflow provides a path to code execution without any authentication required. BleepingComputer confirmed patches shipped today; the F5 advisory and NVD record carry the full technical conditions.

Not every BIG-IP APM instance will be in scope. APM deployments frequently handle external-facing application delivery and VPN access, so the interface that needs the OAuth profile is often one that handles real external traffic. The exposure class is enterprise network perimeter, not a niche lab configuration.

What to do

Apply the F5 patches. For environments where immediate patching is not feasible, CISA recommends applying the vendor-provided iRule as a temporary mitigation while forensic triage is completed; see the F5 advisory for both the iRule instructions and the final patch guidance. The iRule buys time; the patch closes the hole.

CISA’s September 25 federal deadline applies directly to civilian executive branch agencies under BOD 26-04, but it signals something broader: a CVSS 9.8 unauthenticated RCE with confirmed in-the-wild exploitation and an available vendor patch leaves almost no room for delay, regardless of regulatory jurisdiction.

Context

This is the second significant exploitation event targeting F5 BIG-IP APM in September. Earlier this month, a fileless Linux rootkit was found living in memory on compromised BIG-IP APM systems, a campaign that appeared to leverage persistent access from earlier unpatched vulnerabilities. CVE-2026-94127 is a distinct flaw and a separate entry point, but the concentration of attention on BIG-IP APM this year has been consistent.

F5 BIG-IP’s CVE history in 2026 includes a max-severity iControl REST auth bypass in July and VPN appliance vulnerabilities earlier that year. Appliances at the edge of enterprise networks, aggregating authentication and application traffic, are an efficient target for threat actors who want persistent network access. BIG-IP APM’s position in many enterprise architectures makes it a reliable point of focus.

September 25 is three days away. If BIG-IP APM is on your perimeter with an access policy and OAuth profile configured together, this one does not wait.

Related CVEs
  • [ CRITICAL ]CVE-2026-94127F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

Found this useful? Share it.