F5 Patches Zero-Day Flaw in Network Access Tools

Attackers are actively exploiting a critical flaw in F5's access management software to execute remote code, prompting urgent federal action.
Key points
- F5 released a patch for CVE-2026-94127, a zero-day flaw in BIG-IP APM being used for remote code execution.
- CISA ordered US federal agencies to secure their systems against the vulnerability by Friday due to active exploitation.
- Administrators should check for OAuth failures and TMM SIGABRT crashes as indicators of an active attack attempt.
F5 has released urgent security updates to close a critical vulnerability in its BIG-IP Access Policy Manager software. The flaw, identified as CVE-2026-94127, is being actively exploited by attackers to gain unauthorized control over corporate networks. This is not a theoretical risk but an ongoing campaign of remote code execution attacks that have already compromised several systems.
The vulnerability specifically targets configurations where the software acts as an OAuth Authorization Server. This component manages how users and applications authenticate to access internal resources. Because it handles sensitive login processes, a breach here allows attackers to bypass standard security controls and inject malicious commands directly into the infrastructure. As reported by BleepingComputer, F5 confirmed that the flaw is under active abuse in the wild.
Identifying active exploitation attempts
Administrators are advised to look for specific patterns in their logs to determine if their systems have been targeted. The primary indicator is a cluster of failed OAuth authentication attempts immediately followed by suspicious command execution. A sudden crash signal known as a TMM SIGABRT shortly after these events is a strong sign that the exploit has been triggered. These symptoms suggest an attacker is probing for weaknesses before fully establishing a foothold.
If you cannot immediately install the full security patch, F5 has provided a temporary mitigation strategy. This involves applying a specific code rule, or iRule, to the affected virtual servers. While this does not fix the underlying issue, it blocks the specific attack vector currently being used. Organizations should treat this as a stopgap measure and prioritize the permanent patch as soon as possible to ensure long-term security.
Federal agencies face strict deadlines
The severity of the threat has prompted a rapid response from US government officials. The Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog on Tuesday. This action mandates that all federal agencies must secure their networks against the flaw by Friday. The agency emphasized that these types of access management weaknesses are a frequent entry point for malicious actors targeting critical infrastructure.
This incident highlights a broader pattern of risk in the enterprise security landscape. F5 products have been targeted repeatedly in recent years, with attackers using similar flaws to steal data and deploy destructive malware. In late 2025, it was disclosed that state-sponsored hackers had breached F5’s own systems, stealing source code and undisclosed vulnerabilities. This history increases the urgency for organizations to verify their patch status and monitor for signs of compromise.
Widespread exposure remains a concern
The potential scale of the impact is difficult to quantify precisely. Monitoring groups have identified over 14,700 internet-facing IP addresses running this specific software configuration. However, it is unclear how many of these are actively vulnerable honeypots versus real production systems. This uncertainty creates a challenging environment for defenders, as the attack surface remains large and fragmented across thousands of organizations globally.
For businesses, the trade-off between operational stability and security updates is becoming increasingly difficult to manage. Delaying patches to avoid potential service disruptions leaves organizations exposed to known, actively exploited threats. The recent events underscore the need for faster patching cycles and robust monitoring capabilities to detect exploitation attempts before they succeed. Security teams must balance the risk of change against the certain risk of compromise.






