Security News

F5 BIG-IP Zero-Day Under Active Attack: Patch Now, CISA Warns

The Register · 24 Sept 2026
Key Takeaway If your business uses F5 BIG-IP APM, apply the emergency patch immediately rather than waiting for a routine update cycle.

F5 has issued a fix for a critical zero-day vulnerability in its BIG-IP Access Policy Manager (APM), a widely used tool that gives staff single sign-on access to enterprise networks, applications and cloud services. The flaw, tracked as CVE-2026-94127, is a heap-based buffer overflow affecting BIG-IP APM systems set up as an OAuth Authorization Server, and it scores a severe 9.3 out of 10 on the CVSS scale.

F5 confirmed the vulnerability is being actively exploited, though it has not said how many systems have been compromised or whether attackers are using the flaw to deploy ransomware. The US Cybersecurity and Infrastructure Security Agency (CISA) has added the bug to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by Friday.

This latest warning follows a major breach roughly a year ago, in which F5 disclosed that nation-state hackers had stolen BIG-IP source code, undisclosed vulnerability details and customer configuration data. No group has been officially blamed for the current attack, though a separate F5 flaw was previously linked to a China-based hacking group targeting government and defense targets.

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.