INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

F5 BIG-IP APM Zero-Day Exploited for Unauthenticated RCE Attacks

| 2026-09-23 07:34 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A zero-day remote code execution (RCE) vulnerability, CVE-2026-94127, was discovered in F5 BIG-IP APM, allowing an unauthenticated attacker to execute arbitrary code on a vulnerable system. The US Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog shortly after F5 published its advisory on September 22, 2026. This vulnerability affects deployments using BIG-IP APM with an access policy together with an OAuth profile on a virtual server, specifically when configured as an OAuth Authorization Server. The affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0; systems using APM only as an OAuth Client or Resource Server are not affected. F5 has released emergency security updates for the vulnerable configurations, with US federal agencies instructed to address the vulnerability by September 25, 2026.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-94127, CVE-2025-53521 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

17.5.•••.•••
17.1.•••.•••
17.5.•••.•••
21.1.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-94127CVE-2026-94127 CVE-2025-53521CVE-2025-53521
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎November 2021
Threat actors have exploited eight actively flagged F5 BIG-IP vulnerabilities since November 2021, including four that were also used in ransomware attacks.
tactic Ransomware
‎August 2025
State-sponsored hackers breached F5's systems in August 2025, stealing undisclosed BIG-IP security source code and vulnerabilities.
‎October 2025
State-sponsored hackers breached F5's systems in August 2025, resulting in the theft of BIG-IP security source code and vulnerabilities that were later exploited to launch RCE attacks.
‎September 22
Threat actors exploited the previously disclosed F5 BIG-IP APM Zero-Day vulnerability, which was added to CISA's KEV catalog on September 22.
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
attribution KEV
‎September 23, 2026
Threat actors exploited the unpatched F5 BIG-IP APM zero-day vulnerability, CVE-2026-94127, to execute remote code execution.
vulnerability CVE-2026-94127
tactic Remote Code Execution
‎Sep 23, 2026
Threat actors exploited a previously unknown vulnerability in F5 BIG-IP APM to launch remote code execution (RCE) attacks.
‎September 23
F5 updated its CVE record at 00:45 UTC on September 23 to acknowledge the presence of a zero-day vulnerability in the authorization server role.
‎2026/09/23
Threat actors are exploiting a critical-severity BIG-IP Access Policy Manager (APM) zero-day vulnerability, tracked as CVE-2026-94127 with a CVSS score of 9.8, allowing unauthenticated attackers to achieve remote code execution (RCE) on vulnerable deployments configured as an OAuth Authorization Server when a BIG-IP APM access policy and an OAuth profile are configured.
organisation Known Exploited
organisation KEV
organisation BIG-IP Access
organisation APM
infrastructure 9.8
organisation OAuth
organisation BIG-IP APM
infrastructure 21.1.0
infrastructure 17.5.0
infrastructure 17.5.1
infrastructure 17.1.0
infrastructure 17.1.3
organisation BIG-IP Vulnerability Exploited
organisation OAuth Client / Resource
organisation Vulnerability / Network Security
organisation OAuth Client/Resource
organisation Chinese Hackers
organisation NPM Package
organisation BIG-IP
organisation RCE
organisation TMM
organisation iRule
organisation IP
infrastructure 14,700 IP addresses
organisation SecurityAffairs
organisation ADN
victims 23,000 customers
victims 48 customers
organisation NFL
organisation CHANEL
infrastructure 21.1
infrastructure 2.0.30
infrastructure 17.5
infrastructure 9.0.160
infrastructure 17.1
infrastructure 5.0.41
organisation Access > Federation >
organisation CVSS
organisation CVSS v4.0
organisation Appliance
organisation UserInfo
organisation SOD
organisation SIGABRT
‎September 25, 2026
US federal agencies were instructed to address the F5 BIG-IP APM zero-day vulnerability by September 25, 2026.
target_region United States
‎September 25
F5 issued a directive to federal civilian agencies in June, giving them until September 25 to apply mitigations for the exploitation of its BIG-IP APM zero-day vulnerability.
attribution F5
Tactical Metrics
Metrics
infrastructure
‎21.1.0
Software Version
Metrics
infrastructure
‎17.5.0
Software Version
Metrics
infrastructure
‎17.5.1
Software Version
Metrics
infrastructure
‎17.1.0
Software Version
Metrics
infrastructure
‎17.1.3
Software Version
Metrics
infrastructure
‎9.8
Software Version
Metrics
infrastructure
14,700
Ip Addresses
Metrics
victims
23,000
Customers
Metrics
victims
48
Customers
Metrics
infrastructure
‎21.1
Software Version
Metrics
infrastructure
‎2.0.30
Software Version
Metrics
infrastructure
‎17.5
Software Version
Metrics
infrastructure
‎9.0.160
Software Version
Metrics
infrastructure
‎17.1
Software Version
Metrics
infrastructure
‎5.0.41
Software Version
Intelligence Sources