Skip to content
RegionAmericas

MediumII Cyber Warfare & Critical Infrastructure22 September 2026, Tuesday

Zero-day in F5 BIG-IP APM with a CVSS score of 9.8 under active exploitation; CISA gives federal agencies until 25 September

On 22 September 2026 F5 confirmed that the CVE-2026-94127 vulnerability in its BIG-IP Access Policy Manager was being used in attacks. The heap overflow, scored 9.8 under CVSS v3.1, allows unauthenticated remote code execution; CISA added the flaw to its KEV catalogue the same day.

Location: SEATTLE

According to The Hacker News, on systems where BIG-IP APM is configured as an OAuth authorisation server and an access policy and an OAuth profile coexist on the same virtual server, the flaw allows code execution without logging in by corrupting memory with specially crafted network traffic. The flaw scored 9.8 under CVSS v3.1 and 9.3 under CVSS v4.0. Affected versions are 21.1.0, 17.5.0–17.5.1 and 17.1.0–17.1.3; installations using APM only as an OAuth client or resource server are not affected. F5 released engineering fixes for each branch and recommended an iRule workaround until the fix is applied.

According to SecurityWeek's report of 23 September, F5 discovered the flaw through its own internal work and confirmed that attackers had actually weaponised it; the company shared 3 indicators of compromise for detection. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalogue, requiring federal civilian agencies to take action within 3 days, that is, by 25 September 2026. The Hacker News recommended monitoring APM logs for repeated failed UserInfo requests containing invalid tokens and unexplained increases in OAuth counters.

Who is conducting the attacks, how many organisations have been affected and the number of vulnerable internet-facing BIG-IP instances could not be verified as of 24 September. There are only 3 days between the flaw's disclosure on 22 September and the KEV deadline on 25 September; SecurityWeek wrote that the deadline was set under directive BOD 26-04.

Talay assessment

Bottom line

An actively exploited 9.8-rated flaw requiring no authentication shows that network-edge access devices remain attackers' first point of entry in 2026. Because the flaw is triggered only in the OAuth authorisation server configuration, its reach is narrow, but the affected organisations are critical. The most likely path is breach notifications in certain sectors in the coming weeks.

Likely effects

  • US public agenciesNegativeWeeks

    The KEV obligation with a 25 September deadline forces federal agencies into urgent patching; if the deadline is missed, authentication infrastructure is left directly exposed.

  • Corporate network securityNegativeWeeks

    Unauthenticated code execution on BIG-IPs used as OAuth authorisation servers gives attackers a path into the network with broad privileges.

  • Turkish organisationsNegativeWeeks

    Turkish banks and public bodies using BIG-IP on the same 17.1, 17.5 and 21.1 branches are exposed to the same risk until they apply the fix.

Possibilities, ranked

  1. 1
    Targeted breaches announced55%

    Breach notifications and attributions to attacker groups emerge at organisations that delay patching.

    Watch: Additional indicators of compromise or attribution announcements from CISA and F5

  2. 2
    Rapid patching, limited damage35%

    Thanks to the narrow configuration condition and fast rollout of fixes, cases remain limited to a few organisations.

    Watch: Federal compliance status statements after 25 September

  3. 3
    Mass exploitation wave10%

    Proof-of-concept code spreads and ransomware groups exploit the flaw through mass scanning.

    Watch: Security firms' reports of mass scanning and exploitation

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • CVSS v3.1 score▼ 9.8
  • CISA KEV deadline▼ 3 days

Sources

  1. SecurityWeek — Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
  2. The Hacker News — F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers