F5 patches exploited critical BIG-IP flaw enabling remote code execution

← Back to the feed

F5 patches exploited critical BIG-IP flaw enabling remote code execution

The Register · 3 hours ago

F5 has patched a critical zero-day vulnerability in its BIG-IP Access Policy Manager, but the flaw is already being exploited to run malicious code remotely. The issue matters because APM controls access to enterprise networks, applications, APIs and cloud services, potentially exposing organisations that have not applied the fix.

Tracked as CVE-2026-94127, the heap-based buffer overflow affects systems configured as an OAuth authorisation server with an access policy and OAuth profile on the same virtual server. It has a CVSS v4.0 severity score of 9.3; CISA has added it to its Known Exploited Vulnerabilities catalogue and ordered US federal agencies to patch by Friday. F5 has not disclosed how many systems were compromised or whether ransomware is involved, while the warning follows a 2025 intrusion in which suspected nation-state hackers stole F5 source code, vulnerability information and customer data.

  • F5’s critical BIG-IP APM zero-day is under active attack.
  • The flaw enables remote code execution on vulnerable configurations.
  • F5 and CISA urge immediate patching.

Software

Read the full article at the source →

Originally published by The Register as “Someone’s attacking a critical 0-day RCE in F5 BIG-IP APM”.