Skip to main content
F5Security incident

Someone's attacking a critical 0-day RCE in F5 BIG-IP APM

What happened

A critical zero-day remote code execution vulnerability, CVE-2026-94127, in F5's BIG-IP Access Policy Manager (APM) is being actively exploited by unknown attackers.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

security Good news: there's a patch. Bad news: both CISA and F5 warn that it's under active exploitation F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code. BIG-IP APM is a centralized access management and security proxy that allows users to connect to enterprise networks, applications, APIs, and cloud services via a single login. The flaw, tracked as CVE-2026-94127, is a heap-based buffer overflow that affects BIG-IP APM systems configured as an OAuth Authorization Server, with an access policy and OAuth profile on the same virtual server. It received a critical 9.3 CVSS v4.0 score - so patch now. "We have learned that this vulnerability has been exploited," F5 said in a Tuesday security advisory. F5 did not immediately respond to our questions, including how many systems have been compromised, and whether criminals are abusing the vulnerability to deploy ransomware. Also on Tuesday, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, and gave federal agencies a Friday deadline to apply patches. This warning comes about a year after F5 and CISA warned "highly sophisticated nation-state" hackers broke into the vendor's network and stole BIG-IP source code, zero-day vulnerability details, and...

Keep reading with a free account

The rest of this article, and every signal for F5, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Product
BIG-IP Access Policy Manager

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
A critical zero-day heap-based buffer overflow vulnerability (CVE-2026-94127) is under active exploitation, allowing remote code execution on systems configured as an OAuth Authorization Server.

Topics and mentions

Product tags

  • security
  • online technology
  • general technology

Extraction

Confidence
100%
Detected
Sep 23, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for F5 and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at F5 this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/6ab92cbf-35a8-cf17-ac61-0efbacf299d0 returns this record as JSON. POST /v1/companies/enrich returns every signal for f5.com.

{
  "signal_id": "6ab92cbf-35a8-cf17-ac61-0efbacf299d0",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-09-23T18:09:28+00:00",
  "company": {
    "name": "F5",
    "domain": "f5.com"
  },
  "data": {
    "url": "https://www.theregister.com/security/2026/09/23/someones-attacking-a-critical-0-day-rce-in-f5-big-ip-apm/5298659",
    "title": "Someone's attacking a critical 0-day RCE in F5 BIG-IP APM",
    "excerpt": "security Good news: there's a patch. Bad news: both CISA and F5 warn that it's under active exploitation F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code. BIG-IP APM is a centralized access management and security proxy that allows users to connect to enterprise networks, applications, APIs, and cloud services via a single login. The flaw, tracked as CVE-2026-94127 , is a heap-based buffer overflow that affects BIG-IP APM systems configured as an OAuth Authorization Server, with an access policy and OAuth profile on the same virtual server. It received a critical 9.3 CVSS v4.0 score - so patch now. “We have learned that this vulnerability has been exploited,” F5 said in a Tuesday security advisory. F5 did not immediately respond to our questions, including how many systems have been compromised, and whether criminals are abusing the vulnerability to deploy ransomware. Also on Tuesday, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog , and gave federal agencies a Friday deadline to apply patches. This warning comes about a year after F5 and CISA warned “highly sophisticated nation-state\" hackers broke into the vendor’s network and stole BIG-IP source code, zero-day vulnerability details, and...",
    "product": "BIG-IP Access Policy Manager",
    "summary": "A critical zero-day remote code execution vulnerability, CVE-2026-94127, in F5's BIG-IP Access Policy Manager (APM) is being actively exploited by unknown attackers.",
    "planning": false,
    "image_url": "https://image.theregister.com/260240.jpg?imageId=260240&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683",
    "confidence": 1,
    "product_data": {
      "name": "BIG-IP Access Policy Manager",
      "full_text": "BIG-IP Access Policy Manager (APM)",
      "fuzzy_match": false
    },
    "product_tags": [
      "security",
      "online_technology",
      "general_technology"
    ],
    "published_at": "2026-09-23T18:09:28Z",
    "vulnerability": "A critical zero-day heap-based buffer overflow vulnerability (CVE-2026-94127) is under active exploitation, allowing remote code execution on systems configured as an OAuth Authorization Server.",
    "article_sentence": "F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.