{"id":247,"date":"2026-09-27T01:21:40","date_gmt":"2026-09-27T01:21:40","guid":{"rendered":"https:\/\/managedt.com\/blog\/f5-big-ip-apm-zero-day-patch\/"},"modified":"2026-09-27T01:21:41","modified_gmt":"2026-09-27T01:21:41","slug":"f5-big-ip-apm-zero-day-patch","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/f5-big-ip-apm-zero-day-patch\/","title":{"rendered":"F5 patches BIG-IP APM zero-day exploited in remote code execution attacks"},"content":{"rendered":"<p>F5 has released security updates for a critical vulnerability in BIG-IP Access Policy Manager that is already being used in remote code execution attacks. Tracked as CVE-2026-94127, the flaw puts every affected BIG-IP APM deployment configured as an OAuth Authorization Server at risk, while installations used strictly as an OAuth Client or Resource Server are not affected. CISA has added the bug to its Known Exploited Vulnerabilities catalog and given U.S. federal agencies until Friday to secure their networks.<\/p>\n<h2>What BIG-IP APM owners need to do first<\/h2>\n<p>An organization that runs BIG-IP APM with both an access policy and an OAuth profile on a virtual server should treat the device as exposed until patched. F5&#8217;s advisory confirms exploitation in the wild and points to a specific signal to look for: a burst of OAuth authentication failures paired with suspicious commands, followed soon after by a TMM SIGABRT crash. TMM is F5&#8217;s traffic management microkernel, and a SIGABRT is an abnormal termination dump, so the trio of failed authentications, odd shell activity and a sudden TMM crash is the practical tripwire defenders should search their logs for.<\/p>\n<p>Two responses are available right now. The first is to install the new F5 security updates on every affected BIG-IP APM virtual server. The second, for environments that cannot patch immediately, is to apply an iRule available from F5 Support to the affected virtual server. Both options come from F5&#8217;s own guidance published alongside the patches.<\/p>\n<h2>How big is the exposed footprint?<\/h2>\n<p>Internet exposure remains significant. Shadowserver is currently tracking over 14,700 IP addresses with BIG-IP APM fingerprints reachable online. The monitoring project notes that it does not know how many of those instances have already been patched or are running as honeypots, so the 14,700 figure is a maximum exposure line rather than a confirmed victim count. Even with that caveat, the number shows that a widely deployed access control product with a known-exploited bug is sitting within reach of attackers on the public internet.<\/p>\n<h2>Why this flaw lands on the KEV catalog fast<\/h2>\n<p>CISA&#8217;s Known Exploited Vulnerabilities catalog flags bugs that are confirmed to be in active use by attackers, and CVE-2026-94127 was added the same day F5 published its advisory. The agency&#8217;s note describes these flaws as a frequent attack vector for malicious cyber actors and a significant risk to the federal enterprise, which is why federal agencies are bound by a binding operational directive to remediate on the catalog&#8217;s schedule. CISA has now flagged eight F5 vulnerabilities since November 2021, four of which have also shown up in ransomware incidents.<\/p>\n<h2>F5 as a long-running target for sophisticated attackers<\/h2>\n<p>F5 products have been a frequent target for both financially motivated and state-backed groups in recent years. Past abuse of F5 flaws has led to corporate network breaches, device hijacks, internal server mapping, data-wiping malware deployment and theft of sensitive documents. In October 2025, F5 confirmed that state-sponsored intruders had breached its own systems in August 2025 and made off with BIG-IP security source code and vulnerability data, a disclosure that raised the bar on monitoring any new patch for signs of prior inside knowledge.<\/p>\n<p>F5 itself is a Fortune 500 company that provides cybersecurity, application delivery networking and related services to more than 23,000 customers worldwide, including 48 of the Fortune 50. That reach is why a single BIG-IP APM bug with a public exploit is treated as high priority by defenders and by government agencies at the same time.<\/p>\n<h2>How to tell if your BIG-IP APM was already probed<\/h2>\n<p>The practical detection path from F5&#8217;s advisory is narrow but clear. Pull BIG-IP APM logs for OAuth authentication failures in clusters rather than single events, then check for non-administrative commands issued on the device around the same window, and finally look for a TMM SIGABRT dump shortly after. Any environment showing that chain should be treated as compromised until proven otherwise, which typically means rotating credentials, capturing forensic images, and reviewing outbound traffic from the BIG-IP device during the same window.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is CVE-2026-94127?<\/h3>\n<p>CVE-2026-94127 is a critical zero-day vulnerability in F5 BIG-IP Access Policy Manager that is being exploited in remote code execution attacks. It affects instances configured as an OAuth Authorization Server where a BIG-IP APM access policy and an OAuth profile are configured on the same virtual server.<\/p>\n<h3>Does this BIG-IP APM flaw affect every deployment?<\/h3>\n<p>No. F5 states that deployments using BIG-IP APM strictly as an OAuth Client or Resource Server, without OAuth authorization server profiles configured, are not affected by the vulnerability.<\/p>\n<h3>What should admins do if they cannot patch right now?<\/h3>\n<p>F5 advises applying an iRule, available from F5 Support, to the affected BIG-IP APM virtual server as a mitigation measure until the security update can be installed.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is CVE-2026-94127?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CVE-2026-94127 is a critical zero-day vulnerability in F5 BIG-IP Access Policy Manager that is being exploited in remote code execution attacks. It affects instances configured as an OAuth Authorization Server where a BIG-IP APM access policy and an OAuth profile are configured on the same virtual server.\"}},{\"@type\":\"Question\",\"name\":\"Does this BIG-IP APM flaw affect every deployment?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. F5 states that deployments using BIG-IP APM strictly as an OAuth Client or Resource Server, without OAuth authorization server profiles configured, are not affected by the vulnerability.\"}},{\"@type\":\"Question\",\"name\":\"What should admins do if they cannot patch right now?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"F5 advises applying an iRule, available from F5 Support, to the affected BIG-IP APM virtual server as a mitigation measure until the security update can be installed.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks\/\" target=\"_blank\" rel=\"nofollow noopener\">bleepingcomputer.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>F5 has shipped fixes for CVE-2026-94127, a critical BIG-IP APM flaw already used in RCE attacks, and CISA has ordered federal agencies to patch by Friday.<\/p>\n","protected":false},"author":3,"featured_media":246,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-247","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/247","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=247"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/247\/revisions"}],"predecessor-version":[{"id":248,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/247\/revisions\/248"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/246"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=247"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=247"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=247"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}