Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: big-ip (2 articles)Clear

F5 patches exploited BIG-IP APM zero-day allowing remote code execution on access proxies

F5 released updates for a critical BIG-IP Access Policy Manager zero-day that it confirms is being exploited in remote code execution attacks. Tracked as CVE-2026-94127, the flaw affects instances configured as an OAuth Authorization Server, where a BIG-IP APM access policy and an OAuth profile sit on the same virtual server. Deployments using APM strictly as an OAuth client or resource server are not affected. F5 told customers to hunt for multiple OAuth authentication failures and suspicious commands followed by a TMM SIGABRT, and offered an iRule mitigation for those who cannot patch immediately. Shadowserver tracks over 14,700 exposed BIG-IP APM instances, and CISA added the flaw to its catalog.

Check
Identify BIG-IP APM virtual servers configured as OAuth Authorization Servers, apply F5's update now, or deploy the iRule mitigation and check for compromise indicators.
Affected
BIG-IP APM instances acting as an OAuth Authorization Server with an access policy and OAuth profile on one virtual server face active remote code execution attacks.
Fix
Patch to F5's fixed BIG-IP releases, apply the iRule workaround if patching is delayed, and review logs for OAuth failures preceding a TMM SIGABRT.

F5 BIG-IP APM flaw reclassified from DoS to pre-auth RCE - now actively exploited (CVE-2025-53521)

Remember that F5 BIG-IP APM bug from last year everyone treated as a denial-of-service issue? Turns out it's pre-auth remote code execution - CVSS 9.3. F5 quietly reclassified it after new findings in March 2026 and confirmed exploitation in the wild. CISA added it to the KEV catalog with a March 30 patch deadline. That's tomorrow.

Check
Check if you run F5 BIG-IP with APM access policies enabled.
Affected
BIG-IP APM 17.5.0-17.5.1, 17.1.0-17.1.2, 16.1.0-16.1.6, 15.1.0-15.1.10.
Fix
Update to 17.5.2, 17.1.3, 16.1.7, or 15.1.11 respectively. CISA deadline is March 30, 2026.