INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

F5 BIG-IP APM Zero-Day Exploited in RCE Attacks

| 2026-09-23 18:12 CRITICAL HIGH
Executive Summary AI-generated
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog, a critical advisory that warns of a zero-day vulnerability in F5 BIG-IP APM. The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server. General document context reveals the vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server, and recommends deploying an iRule provided through support channels to affected systems.
Technical Mitigations AI-generated
* Implement OAuth Authorization Server profiles on virtual servers: This configuration will prevent attackers from exploiting the vulnerability when BIG-IP APM operates as an OAuth Authorization Server. * Use iRules to detect and mitigate exploitation attempts: F5 recommends deploying a specific iRule provided through its support channels to the affected BIG-IP APM virtual server, which can help identify and respond to potential exploitation attempts. * Monitor logs for suspicious activity: Regularly review system logs for signs of unauthorized access or code execution, such as TMM SIGABRT events, to detect potential compromises. * Apply hotfixes to vulnerable branches: F5 has released emergency security updates for critical vulnerabilities in BIG-IP APM that attackers are already exploiting. Organizations should apply these hotfixes to affected branches to prevent further exploitation. * Consider a temporary mitigation using an iRule: In the absence of immediate availability of the hotfix, organizations may need to use a temporary mitigation such as deploying an iRule provided through F5's support channels to protect against potential exploitation attempts.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-53521CVE-2025-53521 CVE-2026-94127CVE-2026-94127
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎November 2021
Ransomware exploited a recently patched F5 BIG-IP APM Zero-Day vulnerability.
tactic Ransomware
‎August 2025
Threat actors exploited a BIG-IP APM Zero-Day vulnerability to gain unauthorized access.
‎October 2025
Threat actors exploited a BIG-IP APM Zero-Day vulnerability to gain unauthorized access.
‎September 22
Threat actors exploited a BIG-IP APM Zero-Day vulnerability to target F5 systems.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
‎Sep 23, 2026
Threat actors exploited a zero-day vulnerability in F5's BIG-IP APM Zero to gain unauthorized access via OAuth Remote Code Execution.
‎September 23, 2026
Threat actors exploited a recently disclosed F5 BIG-IP APM zero-day vulnerability, CVE-2026-94127, to target systems via OAuth Remote Code Execution.
vulnerability CVE-2026-94127
tactic Remote Code Execution
‎September 23
F5 updated its CVE record to reflect the vulnerability only affects the authorization server role.
‎2026/09/23
F5 BIG-IP APM security advisory.
infrastructure 9.8
organisation BIG-IP Access
organisation APM
organisation OAuth
organisation BIG-IP APM
organisation OAuth Client / Resource
organisation Vulnerability / Network Security
infrastructure 17.1.0
infrastructure 17.1.3
infrastructure 17.5.0
infrastructure 17.5.1
infrastructure 21.1.0
infrastructure 21.1
infrastructure 2.0.30
infrastructure 17.5
infrastructure 9.0.160
infrastructure 17.1
infrastructure 5.0.41
organisation BIG-IP
organisation RCE
organisation TMM
organisation iRule
organisation IP
infrastructure 14,700 IP addresses
organisation SecurityAffairs
organisation ADN
victims 23,000 customers
victims 48 customers
organisation NFL
organisation CHANEL
organisation Access > Federation >
organisation CVSS
organisation CVSS v4.0
organisation Appliance
organisation UserInfo
organisation SOD
organisation SIGABRT
‎September 25, 2026
Threat actors exploited a BIG-IP APM Zero-Day vulnerability to gain unauthorized access via OAuth RCE.
target_region United States
‎September 25
F5 provided patches for its BIG-IP APM Zero-day vulnerability exploited a previously undisclosed OAuth Remote Code Execution (RCE) threat.
attribution F5
Tactical Metrics
Metrics
infrastructure
‎9.8
Software Version
Metrics
infrastructure
‎17.1.0
Software Version
Metrics
infrastructure
‎17.1.3
Software Version
Metrics
infrastructure
‎17.5.0
Software Version
Metrics
infrastructure
‎17.5.1
Software Version
Metrics
infrastructure
‎21.1.0
Software Version
Metrics
infrastructure
14,700
Ip Addresses
Metrics
victims
23,000
Customers
Metrics
victims
48
Customers
Metrics
infrastructure
‎21.1
Software Version
Metrics
infrastructure
‎2.0.30
Software Version
Metrics
infrastructure
‎17.5
Software Version
Metrics
infrastructure
‎9.0.160
Software Version
Metrics
infrastructure
‎17.1
Software Version
Metrics
infrastructure
‎5.0.41
Software Version
Intelligence Sources