Ethical Hacking News
A critical zero-day vulnerability in F5 BIG-IP Access Policy Manager (APM) software has been exploited in the wild, allowing an unauthenticated attacker to execute arbitrary code on a vulnerable system. Organizations that use the software must take immediate action to secure their deployments and patch the vulnerability, which has been added to the US CISA's Known Exploited Vulnerabilities catalog. The attack highlights the importance of staying up-to-date with the latest security patches and taking proactive measures to protect against known exploits.
F5 has confirmed a zero-day remote code execution (RCE) vulnerability in its BIG-IP Access Policy Manager (APM) software, tracked as CVE-2026-94127. The vulnerability allows an unauthenticated attacker to execute arbitrary code on a vulnerable BIG-IP system, posing a significant threat to organizations using the software. The affected versions include 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0, and F5 has released hotfixes and recommended a temporary mitigation. The US Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, instructing US federal agencies to address it by September 25, 2026. Organizations that use BIG-IP APM software must take immediate action to secure their deployments and ensure they are not vulnerable to this critical security breach.
F5, a leading provider of enterprise security solutions, has confirmed that its BIG-IP Access Policy Manager (APM) software has been compromised by a zero-day remote code execution (RCE) vulnerability. The vulnerability, tracked as CVE-2026-94127, was discovered on September 22, 2026, and has already been exploited in the wild by attackers. According to F5, the vulnerability allows an unauthenticated attacker to execute arbitrary code on a vulnerable BIG-IP system, posing a significant threat to the security of organizations that use the software.
The affected versions of BIG-IP APM include 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0. F5 has released hotfixes for the vulnerable branches, and the company recommends that organizations that cannot install the hotfix immediately deploy a temporary mitigation by applying an iRule provided through its support channels.
The vulnerability is particularly concerning because BIG-IP appliances are commonly positioned at the edge of corporate networks and handle authentication and access to internal applications. A successful compromise could therefore give an attacker a valuable position from which to move deeper into an organization's infrastructure. F5 has also provided indicators that defenders can use to look for signs of exploitation, including repeated OAuth authentication failures followed by suspicious commands and a TMM SIGABRT event.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog, instructing US federal agencies to address the vulnerability by September 25, 2026. Internet exposure appears significant, with Shadowserver tracking over 14,700 IP addresses showing BIG-IP APM fingerprints.
F5 has confirmed active exploitation of the vulnerability, and administrators should treat patching as an incident-response priority rather than as routine vulnerability management. The company's advisory and technical details are available on its website, and organizations are advised to take immediate action to secure their BIG-IP APM deployments.
In a related development, ShinyHunters has claimed an alleged PeopleSoft zero-day attack, while EvilTokens made phishing-as-a-service look easy before being taken down. Fake LastPass on GitHub led to an infostealer that killed 145 security tools, and CVE-2026-87902 has raised concerns about the closeness of WordPress to remote code execution.
The vulnerability highlights the importance of staying up-to-date with the latest security patches and taking proactive measures to protect against known exploits. Organizations that use BIG-IP APM software must take immediate action to secure their deployments and ensure that they are not vulnerable to this critical security breach.
Related Information:
https://www.ethicalhackingnews.com/articles/F5-BIG-IP-APM-Zero-Day-Exploited-in-Zero-Day-RCE-Attacks-A-Critical-Security-Breach-ehn.shtml
https://securityaffairs.com/199619/security/f5-big-ip-apm-zero-day-exploited-in-zero-day-rce-attacks.html
https://nvd.nist.gov/vuln/detail/CVE-2026-94127
https://www.cvedetails.com/cve/CVE-2026-94127/
Published: Wed Sep 23 13:44:43 2026 by llama3.2 3B Q4_K_M