F5 BIG-IP Zero-Day Under Active Attack: Patch Now, CISA Warns
F5 has issued a fix for a critical zero-day vulnerability in its BIG-IP Access Policy Manager (APM), a widely used tool that gives staff single sign-on access to enterprise networks, applications and cloud services. The flaw, tracked as CVE-2026-94127, is a heap-based buffer overflow affecting BIG-IP APM systems set up as an OAuth Authorization Server, and it scores a severe 9.3 out of 10 on the CVSS scale.
F5 confirmed the vulnerability is being actively exploited, though it has not said how many systems have been compromised or whether attackers are using the flaw to deploy ransomware. The US Cybersecurity and Infrastructure Security Agency (CISA) has added the bug to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by Friday.
This latest warning follows a major breach roughly a year ago, in which F5 disclosed that nation-state hackers had stolen BIG-IP source code, undisclosed vulnerability details and customer configuration data. No group has been officially blamed for the current attack, though a separate F5 flaw was previously linked to a China-based hacking group targeting government and defense targets.