Cybersecurity

F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Photo: Ordercrazy, Wikimedia Commons, CC0
0 0
XWhatsAppTelegramLinkedIn

F5 published a security advisory on 22 September for CVE-2026-94127, a critical flaw in BIG-IP Access Policy Manager (APM) that lets an unauthenticated attacker run code remotely on the device. "We have learned that this vulnerability has been exploited," the company wrote in that advisory, as quoted by BleepingComputer. The US National Vulnerability Database logged the record at 15:17 UTC the same day and classifies the bug as a heap-based buffer overflow (CWE-122).

The severity ratings come from F5's own product security team, which filed the CVE: 9.8 out of 10 on the CVSS v3.1 scale and 9.3 on the newer CVSS v4.0 scale, both rated critical. By that vector the attack needs no credentials, no user interaction, and can be launched straight over the network.

Not every BIG-IP installation is exposed. According to the advisory text carried in NVD, the flaw only appears when APM is configured as an OAuth Authorization Server, with both an access policy and an OAuth profile attached to the same virtual server. "Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability," F5 writes. The company adds that systems running in Appliance mode are also vulnerable, and that the problem sits in the data plane with no control plane exposure.

The urgency is being set by Washington. CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog on 22 September, the same day, and gave US federal civilian agencies until 25 September to remediate under binding operational directive BOD 26-04. In the SSVC assessment CISA filed with NVD, the agency marks exploitation as "active", automatable as "yes", and technical impact as "total". The catalog entry also carries a forensic triage requirement, while use in ransomware campaigns is listed as "Unknown".

F5 shipped engineering hotfixes rather than full releases: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG for 21.1.0, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG for the 17.5.x line, and Hotfix-BIGIP-17.1.3.5.0.41.14-ENG for 17.1.x. Administrators who cannot patch at once can request a temporary iRule mitigation through an F5 support case. F5 tells customers to hunt for one specific pattern: multiple OAuth authentication failures alongside suspicious commands, followed shortly by a TMM process crash (SIGABRT). BleepingComputer reports that the monitoring non-profit Shadowserver sees more than 14,700 internet-facing IP addresses carrying BIG-IP APM fingerprints, while noting it is not known how many are already patched, are honeypots, or even run the vulnerable OAuth configuration.

What is still missing is the scale of the damage. Neither F5, NVD nor CISA has said how many organisations were breached, who is behind the attacks, or how the flaw came to light. The federal deadline falls on 25 September.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.