INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
F5 BIG-IP APM Zero-Day Exploited for Unauthenticated RCE Attacks
| 2026-09-23 07:34 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A zero-day remote code execution (RCE) vulnerability, CVE-2026-94127, was discovered in F5 BIG-IP APM, allowing an unauthenticated attacker to execute arbitrary code on a vulnerable system. The US Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog shortly after F5 published its advisory on September 22, 2026. This vulnerability affects deployments using BIG-IP APM with an access policy together with an OAuth profile on a virtual server, specifically when configured as an OAuth Authorization Server. The affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0; systems using APM only as an OAuth Client or Resource Server are not affected. F5 has released emergency security updates for the vulnerable configurations, with US federal agencies instructed to address the vulnerability by September 25, 2026.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-94127, CVE-2025-53521 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
17.5.•••.•••
17.1.•••.•••
17.5.•••.•••
21.1.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-94127CVE-2026-94127
CVE-2025-53521CVE-2025-53521
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
November 2021
Threat actors have exploited eight actively flagged F5 BIG-IP vulnerabilities since November 2021, including four that were also used in ransomware attacks.
Click on any entity below to view its context and source!
tactic
Ransomware
Since November 2021, CISA has
flagged eight actively exploited F5 vulnerabilities
, four of which have also been abused in ransomware attacks.
August 2025
State-sponsored hackers breached F5's systems in August 2025, stealing undisclosed BIG-IP security source code and vulnerabilities.
October 2025
State-sponsored hackers breached F5's systems in August 2025, resulting in the theft of BIG-IP security source code and vulnerabilities that were later exploited to launch RCE attacks.
September 22
Threat actors exploited the previously disclosed F5 BIG-IP APM Zero-Day vulnerability, which was added to CISA's KEV catalog on September 22.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 22.
attribution
Known Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 22.
attribution
KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 22.
September 23, 2026
Threat actors exploited the unpatched F5 BIG-IP APM zero-day vulnerability, CVE-2026-94127, to execute remote code execution.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-94127
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
Pierluigi Paganini
September 23, 2026
F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution.
tactic
Remote Code Execution
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
Pierluigi Paganini
September 23, 2026
F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution.
Sep 23, 2026
Threat actors exploited a previously unknown vulnerability in F5 BIG-IP APM to launch remote code execution (RCE) attacks.
September 23
F5 updated its CVE record at 00:45 UTC on September 23 to acknowledge the presence of a zero-day vulnerability in the authorization server role.
2026/09/23
Threat actors are exploiting a critical-severity BIG-IP Access Policy Manager (APM) zero-day vulnerability, tracked as CVE-2026-94127 with a CVSS score of 9.8, allowing unauthenticated attackers to achieve remote code execution (RCE) on vulnerable deployments configured as an OAuth Authorization Server when a BIG-IP APM access policy and an OAuth profile are configured.
Click on any entity below to view its context and source!
organisation
Known Exploited
Just as F5 published its advisory, CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities (
KEV
) list, urging federal agencies to patch it within three days, as mandated by BOD 26-04.
organisation
KEV
Just as F5 published its advisory, CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities (
KEV
) list, urging federal agencies to patch it within three days, as mandated by BOD 26-04.
organisation
BIG-IP Access
F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild.
F5 and CISA on Tuesday warned organizations that threat actors have been exploiting a critical-severity BIG-IP Access Policy Manager (APM) vulnerability as a zero-day.
organisation
APM
F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild.
F5 and CISA on Tuesday warned organizations that threat actors have been exploiting a critical-severity BIG-IP Access Policy Manager (APM) vulnerability as a zero-day.
"Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.
Swati Khandelwal
Sep 23, 2026
Vulnerability / Network Security
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.
infrastructure
9.8
F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild.
organisation
OAuth
Tracked as
CVE-2026-94127
, the flaw affects instances configured as an OAuth Authorization Server when a
BIG-IP APM access policy and an OAuth profile are configured on a virtual server.
The flaw,
CVE-2026-94127
, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications.
The flaw is exploitable via malicious traffic sent to the appliance when “a BIG-IP APM access policy and an OAuth profile are configured on a virtual server,” F5 notes in its
advisory
.
The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server.
organisation
BIG-IP APM
F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks.
The flaw is exploitable via malicious traffic sent to the appliance when “a BIG-IP APM access policy and an OAuth profile are configured on a virtual server,” F5 notes in its
advisory
.
The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server.
infrastructure
21.1.0
BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 are vulnerable, and F5 has released hotfixes.
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
…n server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG…
infrastructure
17.5.0
BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 are vulnerable, and F5 has released hotfixes.
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
…fected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-…
infrastructure
17.5.1
BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 are vulnerable, and F5 has released hotfixes.
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
…sions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG…
infrastructure
17.1.0
BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 are vulnerable, and F5 has released hotfixes.
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
…Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles…
infrastructure
17.1.3
BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 are vulnerable, and F5 has released hotfixes.
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
…BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not…
organisation
BIG-IP Vulnerability Exploited
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day.
organisation
OAuth Client / Resource
"Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.
Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.
organisation
Vulnerability / Network Security
Swati Khandelwal
Sep 23, 2026
Vulnerability / Network Security
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.
organisation
OAuth Client/Resource
According to the company, the issue can be triggered only when BIG-IP APM is configured as an OAuth Authorization Server, not on deployments using APM as an OAuth Client/Resource Server.
organisation
Chinese Hackers
Related:
Check Point Patches Exploited Management Server Zero-Day
Related:
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Related:
Malicious B-tree NPM Package Accumulates Millions of Downloads
Related:
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
organisation
NPM Package
Related:
Check Point Patches Exploited Management Server Zero-Day
Related:
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Related:
Malicious B-tree NPM Package Accumulates Millions of Downloads
Related:
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
organisation
BIG-IP
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks.
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks.
Because the malicious traffic goes to the virtual server itself, limiting access to the BIG-IP management interface does not protect against this flaw.
organisation
RCE
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks.
organisation
TMM
The company recommends paying particular attention to environments showing repeated OAuth authentication failures followed by suspicious commands and, shortly afterward, a TMM SIGABRT event.
"
The company advised customers to
review systems for indicators of compromise
if they detect a combination of multiple OAuth authentication failures and suspicious commands, shortly followed by a TMM SIGABRT.
The combination that should lead to a human review of the system is repeated OAuth authentication failures, followed by suspicious commands, followed by a TMM SIGABRT shortly after.
organisation
iRule
F5 recommends deploying an iRule provided through its support channels to the affected BIG-IP APM virtual server.
When the hotfix cannot be installed immediately, F5 offers an iRule mitigation for the affected virtual server.
organisation
IP
Shadowserver is
currently tracking
more than 14,700 IP addresses showing BIG-IP APM fingerprints, although this number does not indicate how many systems are actually vulnerable or unpatched.
Internet threat monitoring non-profit Shadowserver currently tracks
over 14,700 IP addresses with BIG-IP APM fingerprints
.
Look especially for 10 or more requests from a single IP address within a short time.
infrastructure
14,700 IP addresses
Shadowserver is
currently tracking
more than 14,700 IP addresses showing BIG-IP APM fingerprints, although this number does not indicate how many systems are actually vulnerable or unpatched.
Internet threat monitoring non-profit Shadowserver currently tracks
over 14,700 IP addresses with BIG-IP APM fingerprints
.
organisation
SecurityAffairs
F5 advisory and technical details:
F5 BIG-IP APM security advisory
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, F5 BIG-IP)
organisation
ADN
F5 is a Fortune 500 company that provides cybersecurity, application delivery networking (ADN), and other services to more than 23,000 customers worldwide, including 48 of the Fortune 50 companies and 80% of the Fortune Global 500.
victims
23,000 customers
F5 is a Fortune 500 company that provides cybersecurity, application delivery networking (ADN), and other services to more than 23,000 customers worldwide, including 48 of the Fortune 50 companies and 80% of the Fortune Global 500.
victims
48 customers
F5 is a Fortune 500 company that provides cybersecurity, application delivery networking (ADN), and other services to more than 23,000 customers worldwide, including 48 of the Fortune 50 companies and 80% of the Fortune Global 500.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
infrastructure
21.1
…s an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.…
infrastructure
2.0.30
…for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, befor…
infrastructure
17.5
…ch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-…
infrastructure
9.0.160
….1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resou…
infrastructure
17.1
…ore the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth author…
infrastructure
5.0.41
…1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
organisation
Access > Federation >
In
F5's configuration guide
for APM 17.1, 17.5 and 21.0, the authorization server's OAuth profile is created under Access > Federation >
organisation
CVSS
F5 rates it 9.8 out of 10 on CVSS v3.1 and 9.3 on CVSS v4.0.
organisation
CVSS v4.0
F5 rates it 9.8 out of 10 on CVSS v3.1 and 9.3 on CVSS v4.0.
organisation
Appliance
BIG-IP systems in Appliance mode are also vulnerable.
organisation
UserInfo
APM log:
repeated failed UserInfo requests in /var/log/apm with the error description "The access token is invalid."
organisation
SOD
F5 has seen TMM enter a loop, causing the SOD daemon to send a SIGABRT.
organisation
SIGABRT
F5 has seen TMM enter a loop, causing the SOD daemon to send a SIGABRT.
September 25, 2026
US federal agencies were instructed to address the F5 BIG-IP APM zero-day vulnerability by September 25, 2026.
Click on any entity below to view its context and source!
target_region
United States
US federal agencies were instructed to address the vulnerability by September 25, 2026.
September 25
F5 issued a directive to federal civilian agencies in June, giving them until September 25 to apply mitigations for the exploitation of its BIG-IP APM zero-day vulnerability.
Click on any entity below to view its context and source!
attribution
F5
It gave federal civilian agencies until September 25 to apply F5's mitigations, under
a directive CISA issued in June
.
Tactical Metrics
Metrics
infrastructure
21.1.0
Software Version
Click for context!
BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 are vulnerable, and F5 has released hotfixes.
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
…n server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG…
Metrics
infrastructure
17.5.0
Software Version
BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 are vulnerable, and F5 has released hotfixes.
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
…fected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-…
Metrics
infrastructure
17.5.1
Software Version
BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 are vulnerable, and F5 has released hotfixes.
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
…sions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG…
Metrics
infrastructure
17.1.0
Software Version
BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 are vulnerable, and F5 has released hotfixes.
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
…Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles…
Metrics
infrastructure
17.1.3
Software Version
BIG-IP APM versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 are vulnerable, and F5 has released hotfixes.
F5 says the affected versions include BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0.
…BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not…
Metrics
infrastructure
9.8
Software Version
F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild.
Metrics
infrastructure
14,700
Ip Addresses
Shadowserver is
currently tracking
more than 14,700 IP addresses showing BIG-IP APM fingerprints, although this number does not indicate how many systems are actually vulnerable or unpatched.
Internet threat monitoring non-profit Shadowserver currently tracks
over 14,700 IP addresses with BIG-IP APM fingerprints
.
Metrics
victims
23,000
Customers
F5 is a Fortune 500 company that provides cybersecurity, application delivery networking (ADN), and other services to more than 23,000 customers worldwide, including 48 of the Fortune 50 companies and 80% of the Fortune Global 500.
Metrics
victims
48
Customers
F5 is a Fortune 500 company that provides cybersecurity, application delivery networking (ADN), and other services to more than 23,000 customers worldwide, including 48 of the Fortune 50 companies and 80% of the Fortune Global 500.
Metrics
infrastructure
21.1
Software Version
…s an OAuth authorization server, these are the affected versions and the hotfix for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.…
Metrics
infrastructure
2.0.30
Software Version
…for each:
Branch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, befor…
Metrics
infrastructure
17.5
Software Version
…ch
Affected versions
Fixed in
21.1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-…
Metrics
infrastructure
9.0.160
Software Version
….1
21.1.0, before the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resou…
Metrics
infrastructure
17.1
Software Version
…ore the hotfix
Hotfix-BIGIP-21.1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth author…
Metrics
infrastructure
5.0.41
Software Version
…1.0.2.0.30.22-ENG
17.5
17.5.0 to 17.5.1, before the hotfix
Hotfix-BIGIP-17.5.1.9.0.160.12-ENG
17.1
17.1.0 to 17.1.3, before the hotfix
Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
Systems that use APM only as an OAuth client or resource server, with no OAuth authorization server profiles, are not affected.
Intelligence Sources
SecurityWeek
2026-09-23
BleepingComputer
2026-09-23
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
BleepingComputer
The Hacker News
2026-09-23
Security Affairs
2026-09-23
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
Security Affairs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:06
Comprehensive Tactical Telemetry
Highly Correlated Entities
28x
organisation
Identified Entity
Known Exploited
entity
12x
infrastructure
Software Version
21.1.0
version
12x
attribution
Attributing Entity
CISA
authority
11x
timeline
Temporal Reference
26-04
date
3x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
vulnerability
Exploited CVE
CVE-2026-94127
cve
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
victims
Customers
23,000
customers
Contextual Telemetry
Context Block
13 METRICS
vulnerability
CVSS Score
10
score
source region
Origin Country
United States
country
target region
Target Country
United States
country
infrastructure
Ip Addresses
14,700
ip addresses
general metric
Fortune Global
500
fortune global
general metric
Fortune
50
fortune
general metric
%
80
%
general metric
21.1.0
21
21.1.0
general metric
Branches
17
branches
general metric
Sep
23
sep
general metric
Cvss V3.1
9
cvss v3.1
general metric
Apm
18
apm
general metric
Requests
10
requests
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.