F5 BIG-IP Vulnerability Exploitation
Cybersecurity experts have raised alarms after a critical vulnerability in F5’s BIG-IP Access Policy Manager (APM) was exploited as a zero-day threat. Both F5 and the Cybersecurity and Infrastructure Security Agency (CISA) issued warnings on Tuesday, alerting organizations to the immediate risks posed by this flaw.
This significant vulnerability, detailed in F5’s advisory, can be exploited through malicious traffic directed at systems utilizing a specific configuration: a BIG-IP APM access policy paired with an OAuth profile on a virtual server.
Details of the Vulnerability
Identified as CVE-2026-94127 and assigned a CVSS score of 9.8, this security weakness enables unauthenticated attackers to execute remote code on susceptible systems. F5 internally discovered this flaw, emphasizing its critical nature due to its potential impact.
The vulnerability surfaces only when BIG-IP APM is set up as an OAuth Authorization Server, differentiating it from configurations where APM serves as an OAuth Client or Resource Server. F5 also highlights that the appliance mode of the BIG-IP system is vulnerable, although the threat is isolated to the data plane, with no exposure to the control plane.
Affected Versions and Mitigation
Among the affected versions are BIG-IP APM 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3, prompting F5 to release hotfixes to address these vulnerabilities. The company reassures that no other products are currently affected by the issue.
F5 published indicators of compromise (IoCs) to assist organizations in identifying potential breaches. Frequent occurrences of these IoCs can signal an ongoing attack, urging immediate attention and action.
Official Response and Recommendations
In response to the advisory, CISA swiftly included CVE-2026-94127 in its Known Exploited Vulnerabilities (KEV) list. It mandates federal agencies to patch the vulnerability within a strict three-day window as per BOD 26-04 guidelines.
Related vulnerabilities and cyber threats continue to surface, emphasizing the need for robust security measures. Experts recommend immediate patching and monitoring for IoCs to mitigate risks associated with this critical vulnerability.
As the cybersecurity landscape evolves, staying informed and proactive is crucial in safeguarding digital assets against such advanced threats.
