Critical F5 BIG‑IP APM Zero‑Day (CVE‑2026‑94127) Actively Exploited, Emergency Patch Issued
F5 Networks has issued an emergency security update for a newly disclosed vulnerability in its BIG‑IP Access Policy Manager (APM) product, identified as CVE‑2026‑94127. The flaw, rated 9.8 on the CVSS scale, enables unauthenticated remote code execution and is already being leveraged by threat actors in the wild.
The vulnerability resides in the APM module that controls user access policies for web applications and services. By sending specially crafted requests, attackers can bypass authentication mechanisms and execute arbitrary code on affected appliances. Because BIG‑IP devices are widely deployed as load balancers, reverse proxies, and security gateways, the potential impact spans a broad range of enterprises and service providers.
F5’s advisory notes that active exploitation has been observed, prompting the company to label the issue as a critical zero‑day. The advisory, first reported by Security Affairs, urges all customers to apply the emergency patches without delay. The updates are available through F5’s standard support channels and address the underlying code path that permits the remote execution.
The emergence of CVE‑2026‑94127 follows a series of high‑profile vulnerabilities in BIG‑IP platforms over recent years, which have made the product a frequent target for sophisticated attackers. Organizations that rely on BIG‑IP for traffic management and security must routinely audit their deployment configurations and keep firmware up to date to mitigate such risks. In addition to patching, best‑practice recommendations include restricting management interfaces to trusted networks, employing multi‑factor authentication for administrative access, and monitoring for anomalous traffic patterns that could indicate exploitation attempts.
Analysts note that the rapid disclosure and emergency response underscore the evolving threat landscape for network infrastructure devices. While the exact scope of compromised systems is not yet known, the presence of active exploitation suggests that threat groups are likely scanning the internet for vulnerable BIG‑IP instances. Security teams are advised to verify patch compliance across their environments, review logs for signs of unauthorized activity, and coordinate with F5 support for any assistance needed during remediation.
Comments (0)
Be the first to comment.
Join the discussion