Published Wednesday, September 23, 2026 at 11:29 AM PT

<strong>SECURITY ALERT: CVE-2026-94127 โ€” F5 BIG-IP APM Zero-Day Under Active Exploitation</strong>


BLUF: F5 BIG-IP Access Policy Manager (APM) is vulnerable to a critical, unauthenticated remote code execution zero-day (CVE-2026-94127) that is actively being exploited in the wild. Affected organizations running BIG-IP APM must immediately inventory instances, isolate systems from untrusted networks, and monitor for exploitation attempts. Patch availability status is currently unknown.

DETAILS:

  • Vulnerability: Unauthenticated remote code execution in F5 BIG-IP Access Policy Manager (APM)
  • Exploitation vector: Specially crafted network traffic; no user interaction required
  • Status: Zero-day with confirmed active exploitation in the wild
  • Attack surface: Internet-facing BIG-IP APM appliances
  • Scope of affected product lines: BIG-IP APM (specific versions not yet detailed in available advisories)

IMPACT:

  • Who: Any organization running F5 BIG-IP APM, particularly internet-facing instances
  • What: Complete compromise of the APM appliance; potential lateral movement to protected network segments
  • Risk tier: CRITICAL โ€” unauthenticated RCE on network access control layer
  • Current threat level: ACTIVE โ€” exploitation observed in the wild

RECOMMENDED ACTIONS โ€” IMMEDIATE (Next 4 hours):

  1. Inventory: Identify all F5 BIG-IP APM instances in your environment; prioritize internet-facing systems
  2. Isolate: If possible without disrupting critical services, move affected BIG-IP APM systems behind additional network-layer access controls or WAF rules
  3. Monitor: Enable logging for anomalous traffic patterns to BIG-IP APM; watch for RCE attempt signatures (F5 security bulletin pending)
  4. Vendor check: Monitor F5 security advisories at f5.com/security for CVSS score, affected versions, and patch availability
  5. Alert upstream: Notify your security team, network operations, and business stakeholders of the risk

NEXT STEPS โ€” If patches are available:

  • Prioritize patching based on exposure (internet-facing > internal-only)

SOURCES:

  • SOC Prime CVE Intelligence (CVE-2026-94127 disclosure)
  • F5 Security Advisories (pending full details)

NOTE โ€” Information Gaps: This alert is based on preliminary CVE disclosure. Affected BIG-IP versions, CVSS score, and patch availability are not yet available in the material provided. Monitor F5’s official security bulletin for detailed mitigation and version guidance.


Recent high-severity events at publish time:

Recent high-severity events