F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25

F5 published a security advisory on 22 September for CVE-2026-94127, a critical flaw in BIG-IP Access Policy Manager (APM) that lets an unauthenticated attacker run code remotely on the device. "We have learned that this vulnerability has been exploited," the company wrote in that advisory, as quoted by BleepingComputer. The US National Vulnerability Database logged the record at 15:17 UTC the same day and classifies the bug as a heap-based buffer overflow (CWE-122).
The severity ratings come from F5's own product security team, which filed the CVE: 9.8 out of 10 on the CVSS v3.1 scale and 9.3 on the newer CVSS v4.0 scale, both rated critical. By that vector the attack needs no credentials, no user interaction, and can be launched straight over the network.
Not every BIG-IP installation is exposed. According to the advisory text carried in NVD, the flaw only appears when APM is configured as an OAuth Authorization Server, with both an access policy and an OAuth profile attached to the same virtual server. "Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability," F5 writes. The company adds that systems running in Appliance mode are also vulnerable, and that the problem sits in the data plane with no control plane exposure.
The urgency is being set by Washington. CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog on 22 September, the same day, and gave US federal civilian agencies until 25 September to remediate under binding operational directive BOD 26-04. In the SSVC assessment CISA filed with NVD, the agency marks exploitation as "active", automatable as "yes", and technical impact as "total". The catalog entry also carries a forensic triage requirement, while use in ransomware campaigns is listed as "Unknown".
F5 shipped engineering hotfixes rather than full releases: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG for 21.1.0, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG for the 17.5.x line, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG for 17.1.x. Administrators who cannot patch at once can request a temporary iRule mitigation through an F5 support case. F5 tells customers to hunt for one specific pattern: multiple OAuth authentication failures alongside suspicious commands, followed shortly by a TMM process crash (SIGABRT). BleepingComputer reports that the monitoring non-profit Shadowserver sees more than 14,700 internet-facing IP addresses carrying BIG-IP APM fingerprints, while noting it is not known how many are already patched, are honeypots, or even run the vulnerable OAuth configuration.
What is still missing is the scale of the damage. Neither F5, NVD nor CISA has said how many organisations were breached, who is behind the attacks, or how the flaw came to light. The federal deadline falls on 25 September.
Sources
- NVD — CVE-2026-94127Primary source
- F5 Security Advisory K000162605Primary source
- CISA Known Exploited Vulnerabilities CatalogPrimary source
- BleepingComputerSecondary
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
WordPress 7.1.1 Patches Click2Shell: One Link Installs a Theme
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.