INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
F5 BIG-IP APM Zero-Day Exploited in RCE Attacks
| 2026-09-23 18:12 CRITICAL HIGHExecutive Summary AI-generated
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog, a critical advisory that warns of a zero-day vulnerability in F5 BIG-IP APM. The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server. General document context reveals the vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server, and recommends deploying an iRule provided through support channels to affected systems.
Technical Mitigations AI-generated
* Implement OAuth Authorization Server profiles on virtual servers: This configuration will prevent attackers from exploiting the vulnerability when BIG-IP APM operates as an OAuth Authorization Server.
* Use iRules to detect and mitigate exploitation attempts: F5 recommends deploying a specific iRule provided through its support channels to the affected BIG-IP APM virtual server, which can help identify and respond to potential exploitation attempts.
* Monitor logs for suspicious activity: Regularly review system logs for signs of unauthorized access or code execution, such as TMM SIGABRT events, to detect potential compromises.
* Apply hotfixes to vulnerable branches: F5 has released emergency security updates for critical vulnerabilities in BIG-IP APM that attackers are already exploiting. Organizations should apply these hotfixes to affected branches to prevent further exploitation.
* Consider a temporary mitigation using an iRule: In the absence of immediate availability of the hotfix, organizations may need to use a temporary mitigation such as deploying an iRule provided through F5's support channels to protect against potential exploitation attempts.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-53521CVE-2025-53521
CVE-2026-94127CVE-2026-94127
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
November 2021
Ransomware exploited a recently patched F5 BIG-IP APM Zero-Day vulnerability.
Click on any entity below to view its context and source!
tactic
Ransomware
Since November 2021, CISA has
flagged eight actively exploited F5 vulnerabilities
, four of which have also been abused in ransomware attacks.
August 2025
Threat actors exploited a BIG-IP APM Zero-Day vulnerability to gain unauthorized access.
October 2025
Threat actors exploited a BIG-IP APM Zero-Day vulnerability to gain unauthorized access.
September 22
Threat actors exploited a BIG-IP APM Zero-Day vulnerability to target F5 systems.
Click on any entity below to view its context and source!
attribution
Known Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 22.
tactic
T1588.006 - Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 22.
attribution
KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 22.
Sep 23, 2026
Threat actors exploited a zero-day vulnerability in F5's BIG-IP APM Zero to gain unauthorized access via OAuth Remote Code Execution.
September 23, 2026
Threat actors exploited a recently disclosed F5 BIG-IP APM zero-day vulnerability, CVE-2026-94127, to target systems via OAuth Remote Code Execution.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-94127
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
Pierluigi Paganini
September 23, 2026
F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution.
tactic
Remote Code Execution
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
Pierluigi Paganini
September 23, 2026
F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution.
September 23
F5 updated its CVE record to reflect the vulnerability only affects the authorization server role.
2026/09/23
F5 BIG-IP APM security advisory.
Click on any entity below to view its context and source!
infrastructure
9.8
F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild.
organisation
BIG-IP Access
F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild.
organisation
APM
F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild.
"Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.
Swati Khandelwal
Sep 23, 2026
Vulnerability / Network Security
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.
organisation
OAuth
Tracked as
CVE-2026-94127
, the flaw affects instances configured as an OAuth Authorization Server when a
BIG-IP APM access policy and an OAuth profile are configured on a virtual server.
The flaw,
CVE-2026-94127
, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications.
The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server.
organisation
BIG-IP APM
F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks.
The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server.
organisation
OAuth Client / Resource
"Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.
Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.
organisation
Vulnerability / Network Security
Swati Khandelwal
Sep 23, 2026
Vulnerability / Network Security
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.
infrastructure
17.1.0
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
infrastructure
17.1.3
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
infrastructure
17.5.0
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
infrastructure
17.5.1
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
infrastructure
21.1.0
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
infrastructure
21.1
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
infrastructure
2.0.30
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
infrastructure
17.5
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
infrastructure
9.0.160
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
infrastructure
17.1
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
infrastructure
5.0.41
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
organisation
BIG-IP
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks.
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks.
Because the malicious traffic goes to the virtual server itself, limiting access to the BIG-IP management interface does not protect against this flaw.
organisation
RCE
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks.
organisation
TMM
The company recommends paying particular attention to environments showing repeated OAuth authentication failures followed by suspicious commands and, shortly afterward, a TMM SIGABRT event.
"
The company advised customers to
review systems for indicators of compromise
if they detect a combination of multiple OAuth authentication failures and suspicious commands, shortly followed by a TMM SIGABRT.
The combination that should lead to a human review of the system is repeated OAuth authentication failures, followed by suspicious commands, followed by a TMM SIGABRT shortly after.
organisation
iRule
F5 recommends deploying an iRule provided through its support channels to the affected BIG-IP APM virtual server.
When the hotfix cannot be installed immediately, F5 offers an iRule mitigation for the affected virtual server.
organisation
IP
Shadowserver is
currently tracking
more than 14,700 IP addresses showing BIG-IP APM fingerprints, although this number does not indicate how many systems are actually vulnerable or unpatched.
Internet threat monitoring non-profit Shadowserver currently tracks
over 14,700 IP addresses with BIG-IP APM fingerprints
.
Look especially for 10 or more requests from a single IP address within a short time.
infrastructure
14,700 IP addresses
Shadowserver is
currently tracking
more than 14,700 IP addresses showing BIG-IP APM fingerprints, although this number does not indicate how many systems are actually vulnerable or unpatched.
Internet threat monitoring non-profit Shadowserver currently tracks
over 14,700 IP addresses with BIG-IP APM fingerprints
.
organisation
SecurityAffairs
F5 advisory and technical details:
F5 BIG-IP APM security advisory
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, F5 BIG-IP)
organisation
ADN
F5 is a Fortune 500 company that provides cybersecurity, application delivery networking (ADN), and other services to more than 23,000 customers worldwide, including 48 of the Fortune 50 companies and 80% of the Fortune Global 500.
victims
23,000 customers
F5 is a Fortune 500 company that provides cybersecurity, application delivery networking (ADN), and other services to more than 23,000 customers worldwide, including 48 of the Fortune 50 companies and 80% of the Fortune Global 500.
victims
48 customers
F5 is a Fortune 500 company that provides cybersecurity, application delivery networking (ADN), and other services to more than 23,000 customers worldwide, including 48 of the Fortune 50 companies and 80% of the Fortune Global 500.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
Access > Federation >
In
F5's configuration guide
for APM 17.1, 17.5 and 21.0, the authorization server's OAuth profile is created under Access > Federation >
organisation
CVSS
F5 rates it 9.8 out of 10 on CVSS v3.1 and 9.3 on CVSS v4.0.
organisation
CVSS v4.0
F5 rates it 9.8 out of 10 on CVSS v3.1 and 9.3 on CVSS v4.0.
organisation
Appliance
BIG-IP systems in Appliance mode are also vulnerable.
organisation
UserInfo
APM log:
repeated failed UserInfo requests in /var/log/apm with the error description "The access token is invalid."
organisation
SOD
F5 has seen TMM enter a loop, causing the SOD daemon to send a SIGABRT.
organisation
SIGABRT
F5 has seen TMM enter a loop, causing the SOD daemon to send a SIGABRT.
September 25, 2026
Threat actors exploited a BIG-IP APM Zero-Day vulnerability to gain unauthorized access via OAuth RCE.
Click on any entity below to view its context and source!
target_region
United States
US federal agencies were instructed to address the vulnerability by September 25, 2026.
September 25
F5 provided patches for its BIG-IP APM Zero-day vulnerability exploited a previously undisclosed OAuth Remote Code Execution (RCE) threat.
Click on any entity below to view its context and source!
attribution
F5
It gave federal civilian agencies until September 25 to apply F5's mitigations, under
a directive CISA issued in June
.
Tactical Metrics
Metrics
infrastructure
9.8
Software Version
Click for context!
F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild.
Metrics
infrastructure
17.1.0
Software Version
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
Metrics
infrastructure
17.1.3
Software Version
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
Metrics
infrastructure
17.5.0
Software Version
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
Metrics
infrastructure
17.5.1
Software Version
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
Metrics
infrastructure
21.1.0
Software Version
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
Metrics
infrastructure
14,700
Ip Addresses
Shadowserver is
currently tracking
more than 14,700 IP addresses showing BIG-IP APM fingerprints, although this number does not indicate how many systems are actually vulnerable or unpatched.
Internet threat monitoring non-profit Shadowserver currently tracks
over 14,700 IP addresses with BIG-IP APM fingerprints
.
Metrics
victims
23,000
Customers
F5 is a Fortune 500 company that provides cybersecurity, application delivery networking (ADN), and other services to more than 23,000 customers worldwide, including 48 of the Fortune 50 companies and 80% of the Fortune Global 500.
Metrics
victims
48
Customers
F5 is a Fortune 500 company that provides cybersecurity, application delivery networking (ADN), and other services to more than 23,000 customers worldwide, including 48 of the Fortune 50 companies and 80% of the Fortune Global 500.
Metrics
infrastructure
21.1
Software Version
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
Metrics
infrastructure
2.0.30
Software Version
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
Metrics
infrastructure
17.5
Software Version
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
Metrics
infrastructure
9.0.160
Software Version
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
Metrics
infrastructure
17.1
Software Version
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
Metrics
infrastructure
5.0.41
Software Version
Who Is Affected
For systems where APM acts as an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
Intelligence Sources
BleepingComputer
2026-09-23
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
BleepingComputer
The Hacker News
2026-09-23
Security Affairs
2026-09-23
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
Security Affairs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-24T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
22x
organisation
Identified Entity
BIG-IP Access
entity
12x
attribution
Attributing Entity
the US Cybersecurity and Infrastructure Security Agency
authority
12x
infrastructure
Software Version
9.8
version
10x
timeline
Temporal Reference
September 25, 2026
date
3x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
vulnerability
Exploited CVE
CVE-2026-94127
cve
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
victims
Customers
23,000
customers
Contextual Telemetry
Context Block
13 METRICS
source region
Origin Country
United States
country
target region
Target Country
United States
country
vulnerability
CVSS Score
10
score
infrastructure
Ip Addresses
14,700
ip addresses
general metric
Fortune Global
500
fortune global
general metric
Fortune
50
fortune
general metric
%
80
%
general metric
21.1.0
21
21.1.0
general metric
Branches
17
branches
general metric
Sep
23
sep
general metric
Cvss V3.1
9
cvss v3.1
general metric
Apm
18
apm
general metric
Requests
10
requests
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.