MediumII Cyber Warfare & Critical Infrastructure22 September 2026, Tuesday
Zero-day in F5 BIG-IP APM with a CVSS score of 9.8 under active exploitation; CISA gives federal agencies until 25 September
On 22 September 2026 F5 confirmed that the CVE-2026-94127 vulnerability in its BIG-IP Access Policy Manager was being used in attacks. The heap overflow, scored 9.8 under CVSS v3.1, allows unauthenticated remote code execution; CISA added the flaw to its KEV catalogue the same day.
According to The Hacker News, on systems where BIG-IP APM is configured as an OAuth authorisation server and an access policy and an OAuth profile coexist on the same virtual server, the flaw allows code execution without logging in by corrupting memory with specially crafted network traffic. The flaw scored 9.8 under CVSS v3.1 and 9.3 under CVSS v4.0. Affected versions are 21.1.0, 17.5.0–17.5.1 and 17.1.0–17.1.3; installations using APM only as an OAuth client or resource server are not affected. F5 released engineering fixes for each branch and recommended an iRule workaround until the fix is applied.
According to SecurityWeek's report of 23 September, F5 discovered the flaw through its own internal work and confirmed that attackers had actually weaponised it; the company shared 3 indicators of compromise for detection. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalogue, requiring federal civilian agencies to take action within 3 days, that is, by 25 September 2026. The Hacker News recommended monitoring APM logs for repeated failed UserInfo requests containing invalid tokens and unexplained increases in OAuth counters.
Who is conducting the attacks, how many organisations have been affected and the number of vulnerable internet-facing BIG-IP instances could not be verified as of 24 September. There are only 3 days between the flaw's disclosure on 22 September and the KEV deadline on 25 September; SecurityWeek wrote that the deadline was set under directive BOD 26-04.
Talay assessment
Bottom line
An actively exploited 9.8-rated flaw requiring no authentication shows that network-edge access devices remain attackers' first point of entry in 2026. Because the flaw is triggered only in the OAuth authorisation server configuration, its reach is narrow, but the affected organisations are critical. The most likely path is breach notifications in certain sectors in the coming weeks.
Likely effects
- US public agenciesNegativeWeeks
The KEV obligation with a 25 September deadline forces federal agencies into urgent patching; if the deadline is missed, authentication infrastructure is left directly exposed.
- Corporate network securityNegativeWeeks
Unauthenticated code execution on BIG-IPs used as OAuth authorisation servers gives attackers a path into the network with broad privileges.
- Turkish organisationsNegativeWeeks
Turkish banks and public bodies using BIG-IP on the same 17.1, 17.5 and 21.1 branches are exposed to the same risk until they apply the fix.
Possibilities, ranked
- 1Targeted breaches announced55%
Breach notifications and attributions to attacker groups emerge at organisations that delay patching.
Watch: Additional indicators of compromise or attribution announcements from CISA and F5
- 2Rapid patching, limited damage35%
Thanks to the narrow configuration condition and fast rollout of fixes, cases remain limited to a few organisations.
Watch: Federal compliance status statements after 25 September
- 3Mass exploitation wave10%
Proof-of-concept code spreads and ransomware groups exploit the flaw through mass scanning.
Watch: Security firms' reports of mass scanning and exploitation
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- CVSS v3.1 score▼ 9.8
- CISA KEV deadline▼ 3 days