News

F5 Patched a Critical BIG-IP Flaw Attackers Were Already Using for Login-Free Code Runs

F5 shipped emergency hotfixes for a critical BIG-IP APM zero-day already exploited for unauthenticated remote code execution. It hits only setups where APM runs as an OAuth authorization server. CISA gave federal agencies until September 25.

F5 Patched a Critical BIG-IP Flaw Attackers Were Already Using for Login-Free Code Runs

Attackers were already running code on F5 BIG-IP systems without logging in when F5 shipped the fix. The company disclosed the flaw on September 22 and released engineering hotfixes the same day, The Hacker News reported, and the exploitation was happening in the wild before the patch existed.

The bug sits in the Access Policy Manager module, the part of BIG-IP that governs how users reach an organization's applications and networks. It is a heap-based buffer overflow, tracked as CVE-2026-94127, rated 9.8 out of 10 on CVSS v3.1 and 9.3 on the newer v4.0 scale. Specific malicious traffic sent to the right virtual server can trigger unauthenticated remote code execution.

The scope is narrower than the severity suggests, and that detail matters. The flaw only bites when APM is configured as an OAuth authorization server, the role where it issues access tokens to applications. Systems that use APM only as an OAuth client or resource server, with no authorization server profile, are not affected. F5 pinned that condition down in a CVE update at 00:45 UTC on September 23, after CISA and CERT-EU had already described the trigger more broadly.

One assumption worth killing early: locking down the management interface does not save you here. Because the malicious traffic goes to the virtual server itself rather than the admin console, restricting the management interface does nothing, and appliance mode systems are vulnerable too.

CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 22 and gave federal civilian agencies until September 25 to apply mitigations. That is a short fuse for a patch cycle, and it reflects the fact that this is confirmed active exploitation rather than a theoretical risk.

F5 released hotfixes for the 21.1, 17.5, and 17.1 branches. Anyone who cannot install them right away can request a temporary iRule mitigation for the affected virtual server through an F5 support ticket. CISA told agencies to apply that iRule first to allow for forensic triage, then install the final vendor patch as soon as possible.

There is a trap for admins who thought they were already covered. An earlier related bug, CVE-2025-53521, was added to CISA's catalog in March, and its fixes for the 17.1 and 17.5 branches land inside the ranges affected by this new flaw. A system patched for the old issue still needs this hotfix if APM runs as an OAuth authorization server on it.

The race looks familiar. It is the same pattern that drove the PaperCut NG/MF emergency patch under active attack and the SonicWall SMA1000 zero-days exploited in the wild: a widely deployed access gateway, an unauthenticated path, and a contest between defenders patching and attackers who already found the door.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free