Security & Risk6 minNewsroom

CISA Flags 9.8 F5 BIG-IP Vulnerability Under Active Exploitation

Corredor de data center com racks de equipamentos de rede, portas perfuradas abertas e feixes densos de cabos laranja e azuis em bandejas suspensas.

CVE-2026-94127 allows remote code execution without authentication. U.S. federal agencies have until September 25 to patch.

CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog on September 22, with a deadline of September 25 for U.S. federal civil agencies to apply the patch. The flaw is in BIG-IP APM, F5's access management module, and received a CVSS v3.1 score of 9.8. F5 itself assigns a 9.3 on the v4.0 scale and published notice K000162605 on the same day after identifying active exploitation.


The issue is a heap buffer overflow, classified as CWE-122, and it only manifests in a specific configuration: a virtual server that simultaneously has an APM access policy and an OAuth profile, with the APM acting as the authorization server. Specifically crafted traffic corrupts memory and executes arbitrary code directly in the Traffic Management Microkernel (TMM), the data plane of the appliance. No authentication, no user interaction required.


The Appliance that Comes First


The detail that changes the risk calculation is where the code runs. The TMM is the process that forwards traffic, not a management service. Anyone executing code there is positioned before load balancing, before TLS termination, and before any authorization decisions, with visibility into user sessions that have yet to be authenticated. The BIG-IP APM is exactly the equipment banks, telecom operators, and public agencies place at the edge for corporate VPN and single sign-on.


A search on ZoomEye for http.body="BIG-IP" returned 59,063 instances exposed globally during the vulnerability analysis. This number describes the product's footprint on the internet, not the vulnerable population: an asset may already be patched, may not have an OAuth profile associated with an access policy, or may be behind additional controls. It serves as an order of magnitude for the surface area and is an uncomfortable order of magnitude for an edge product with active unauthenticated RCE.


The patched versions indicated by F5 are engineering hotfixes on branches 21.1.0, 17.5.0, and 17.1.0. For those unable to apply immediately, there’s an obvious and verifiable configuration mitigation: separating the OAuth profile from the access policy on the same virtual server breaks the exploitation precondition.


Four CVEs, a Three-Day Deadline


F5's entry into the catalog was accompanied by three other vulnerabilities added on September 22, all with evidence of active exploitation, and all in network infrastructure products. The four share the same deadline of September 25, according to CISA's notice. Three business days to inventory, patch, and conduct forensic triage on edge equipment presumes that the organization already knows where its appliances are located.


Here lies the point of interest for those not in the U.S. federal agencies. The CISA deadline only obliges the U.S. government, but the catalog has become a reference clock for cyber insurers and supplier contractual clauses worldwide. A CVE in the catalog with an expiration date is the trigger that many policies use to discuss coverage in case of a subsequent incident.


The Same Equipment, Three Different Exposures


In the Brazilian financial sector, BIG-IP APM frequently appears as a remote access concentrator for third parties and as a front-end for online banking. The Central Bank's requirement for the continuity of essential services turns a compromised edge appliance into a reportable regulatory event, not just an IT incident.


In Germany, the BSI maintains KRITIS, which imposes on critical infrastructure operators the obligation to report relevant incidents, and the remediation of an exploited flaw in access control products falls directly within this scope. European telecommunications operators using the APM for network engineering access are in the same category.


In India, the vector is different: IT delivery centers serving Western clients use the product to authenticate tens of thousands of third-party engineers in client environments. A compromise there does not expose the provider; it exposes the clientele that trusts that access tunnel. The same appliance creates vendor risk rather than its own risk.


It’s worth noting what is still unknown. Both F5 and CISA confirm active exploitation, but neither has attributed the activity to a named group nor published public indicators of compromise as of the closing of this article. Teams that can only hunt with pre-existing IOCs will be without material for a few days, and it is precisely this window that often separates those who patch by calendar from those who patch by threat.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk