Ethical Hacking News
Critical 0-day RCE vulnerability in F5 BIG-IP APM has been exploited, and a patch is available. Organizations must take immediate action to patch their systems to prevent further exploitation of this critical vulnerability.
F5 BIG-IP Access Policy Manager (APM) is affected by a critical 0-day Remote Code Execution (RCE) vulnerability (CVE-2026-94127). The vulnerability allows unknown miscreants to remotely execute malicious code on affected systems. The vulnerability is a heap-based buffer overflow that affects systems configured as an OAuth Authorization Server. The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog. Organizations are advised to patch their F5 BIG-IP APM systems immediately to prevent further exploitation. The vulnerability is considered extremely severe, with a CVSS v4.0 score of 9.3.
The cybersecurity landscape has been dealt a severe blow with the discovery of a critical 0-day Remote Code Execution (RCE) vulnerability in F5 BIG-IP Access Policy Manager (APM). This vulnerability, tracked as CVE-2026-94127, has been actively exploited by unknown miscreants, posing an imminent risk to enterprise networks, applications, APIs, and cloud services. The F5 BIG-IP APM is a centralized access management and security proxy that allows users to connect to enterprise networks, applications, APIs, and cloud services via a single login.
The vulnerability in question is a heap-based buffer overflow that affects BIG-IP APM systems configured as an OAuth Authorization Server, with an access policy and OAuth profile on the same virtual server. This flaw received a critical 9.3 CVSS v4.0 score, making it an extremely severe vulnerability. The US Cybersecurity and Infrastructure Security Agency (CISA) has already added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, and has given federal agencies a Friday deadline to apply patches.
This warning comes about a year after F5 and CISA warned that highly sophisticated nation-state hackers broke into the vendor's network and stole BIG-IP source code, zero-day vulnerability details, and customer configuration data belonging to some users. The attack posed an imminent risk to federal agencies, US cybersecurity officials said at the time.
Neither the feds nor private researchers have publicly attributed the intrusion to a particular group or country, but a year earlier Google's Mandiant threat hunters linked exploitation of the critical F5 BIG-IP flaw CVE-2023-46747 to UNC5174, an access broker it assessed with moderate confidence as operating from China. The group attempted to sell access to US defense contractor appliances and UK government entities.
F5 has fixed the critical zero-day bug in its BIG-IP Access Policy Manager (APM) and has warned that it's under active exploitation. The good news is that there's a patch available, but the bad news is that both CISA and F5 warn that it's under active exploitation. It is imperative that organizations take immediate action to patch their F5 BIG-IP APM systems to prevent further exploitation of this critical vulnerability.
In the age of AI, teaching networking principles remains more important than learning protocols. Kids can learn why BGP matters in a semester, but that won’t leave them ready to implement it. The attack on the F5 BIG-IP APM serves as a stark reminder of the importance of cybersecurity awareness and the need for organizations to prioritize the security of their networks and systems.
Discord users asked to prove they’re adults get less intrusive options. The recent attack on the F5 BIG-IP APM is just one example of the many cybersecurity threats that organizations face every day. The use of AI and machine learning in cybersecurity can help improve the detection and response to these threats, but it is also important to teach networking principles and ensure that organizations have a solid understanding of their systems and networks.
F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code. The flaw, tracked as CVE-2026-94127, is a heap-based buffer overflow that affects BIG-IP APM systems configured as an OAuth Authorization Server, with an access policy and OAuth profile on the same virtual server. It received a critical 9.3 CVSS v4.0 score - so patch now.
The F5 BIG-IP APM is a critical component of many enterprise networks, and its vulnerability to this critical 0-day RCE makes it essential for organizations to take immediate action to patch their systems. The US Cybersecurity and Infrastructure Security Agency (CISA) has already added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, and has given federal agencies a Friday deadline to apply patches.
This warning comes about a year after F5 and CISA warned that highly sophisticated nation-state hackers broke into the vendor's network and stole BIG-IP source code, zero-day vulnerability details, and customer configuration data belonging to some users. The attack posed an imminent risk to federal agencies, US cybersecurity officials said at the time.
Neither the feds nor private researchers have publicly attributed the intrusion to a particular group or country, but a year earlier Google's Mandiant threat hunters linked exploitation of the critical F5 BIG-IP flaw CVE-2023-46747 to UNC5174, an access broker it assessed with moderate confidence as operating from China. The group attempted to sell access to US defense contractor appliances and UK government entities.
F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code. The F5 BIG-IP APM is a critical component of many enterprise networks, and its vulnerability to this critical 0-day RCE makes it essential for organizations to take immediate action to patch their systems.
The good news is that there's a patch available, but the bad news is that both CISA and F5 warn that it's under active exploitation. It is imperative that organizations take immediate action to patch their F5 BIG-IP APM systems to prevent further exploitation of this critical vulnerability.
In the age of AI, teaching networking principles remains more important than learning protocols. Kids can learn why BGP matters in a semester, but that won’t leave them ready to implement it. The attack on the F5 BIG-IP APM serves as a stark reminder of the importance of cybersecurity awareness and the need for organizations to prioritize the security of their networks and systems.
Related Information:
https://www.ethicalhackingnews.com/articles/A-Critical-0-Day-RCE-Exploited-in-F5-BIG-IP-APM-A-Call-to-Action-for-Immediate-Patching-ehn.shtml
https://www.theregister.com/security/2026/09/23/someones-attacking-a-critical-0-day-rce-in-f5-big-ip-apm/5298659
https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm/
https://nvd.nist.gov/vuln/detail/CVE-2026-94127
https://www.cvedetails.com/cve/CVE-2026-94127/
https://nvd.nist.gov/vuln/detail/CVE-2023-46747
https://www.cvedetails.com/cve/CVE-2023-46747/
Published: Wed Sep 23 16:26:06 2026 by llama3.2 3B Q4_K_M