F5 has issued security updates addressing a critical zero-day in BIG-IP APM that threat actors are actively exploiting to achieve remote code execution. The Access Policy Manager component serves as a centralized proxy for managing access to organizational networks, applications, cloud infrastructure, and APIs.
Designated as CVE-2026-94127, the vulnerability impacts systems where an OAuth Authorization Server is configured alongside a BIG-IP APM access policy and OAuth profile on a virtual server. F5 stated in its Tuesday security advisory: "We have learned that this vulnerability has been exploited." The company clarified that "Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability."
F5 recommended that customers examine their infrastructure for compromise indicators, specifically looking for patterns of multiple failed OAuth authentication attempts followed by suspicious command execution and a TMM SIGABRT event. For organizations unable to deploy patches immediately, F5 Support can provide an iRule to apply as a temporary mitigation on the vulnerable virtual server.
Shadowserver, an internet threat monitoring nonprofit, has identified over 14,700 IP addresses exhibiting BIG-IP APM signatures, though the actual number of vulnerable, patched, or honeypot instances remains unclear.

The Cybersecurity and Infrastructure Security Agency added CVE-2026-94127 to its Known Exploited Vulnerabilities Catalog on Tuesday and mandated that U.S. federal agencies remediate the flaw by Friday. CISA warned that "These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise."
F5 products have become recurring targets for both cybercriminal and state-sponsored groups. Attackers have leveraged F5 vulnerabilities to compromise corporate networks, commandeer infrastructure, enumerate internal systems, distribute destructive malware, and exfiltrate confidential data. In October 2025, F5 disclosed that state-sponsored actors had breached its infrastructure in August 2025, obtaining undisclosed BIG-IP security source code and vulnerability information.
Since November 2021, CISA has documented eight F5 vulnerabilities under active exploitation, with four of those also weaponized in ransomware campaigns. F5, a Fortune 500 firm delivering cybersecurity, application delivery networking, and related solutions, serves more than 23,000 customers globally, including 48 Fortune 50 enterprises and 80 percent of the Fortune Global 500.