F5 BIG-IP APM zero-day RCE (CVE-2026-94127)
Vulnerability
Summary
Hide ▲
Show ▼
A critical zero-day in F5 BIG-IP APM tracked as CVE-2026-94127 is being actively exploited for remote code execution on deployments configured as an OAuth Authorization Server. F5 released security updates and said systems using APM strictly as an OAuth Client / Resource Server are not affected. Administrators who cannot patch immediately can apply an iRule mitigation and should watch for multiple OAuth authentication failures, suspicious commands, and a TMM SIGABRT.
Related Happenings
PoisonedRefresh Linux rootkit on F5 BIG-IP APM
Malware Activity
H score31
First: 08.09.2026 23:08
Last: 08.09.2026 23:08
Sources 1
About this happening:
The PoisonedRefresh malware activity targets F5 BIG-IP APM appliances and uses a fileless PHP web shell that Sophos said is injected into memory rather than writte...
PoisonedRefresh Linux rootkit on F5 BIG-IP APM
Malware ActivityAbout this happening: The PoisonedRefresh malware activity targets F5 BIG-IP APM appliances and uses a fileless PHP web shell that Sophos said is injected into memory rather than writte...
F5 BIG-IP APM active exploitation wave (CVE-2025-53521)
Exploitation Wave
H score79
First: 02.04.2026 11:25
Last: 02.04.2026 11:25
Sources 1
About this happening:
CVE-2025-53521 is being exploited against F5 BIG-IP APM systems, and F5 says new information in March 2026 changed the flaw from denial of service to remote...
F5 BIG-IP APM active exploitation wave (CVE-2025-53521)
Exploitation WaveAbout this happening: CVE-2025-53521 is being exploited against F5 BIG-IP APM systems, and F5 says new information in March 2026 changed the flaw from denial of service to remote...
CISA order to secure BIG-IP APM
Public Sector Action
H score89
First: 30.03.2026 13:59
Last: 30.03.2026 13:59
Sources 1
About this happening:
CISA added CVE-2025-53521 to its actively exploited list and ordered federal agencies to secure BIG-IP APM systems by midnight on Monday, March 30, 2026, escal...
CISA order to secure BIG-IP APM
Public Sector ActionAbout this happening: CISA added CVE-2025-53521 to its actively exploited list and ordered federal agencies to secure BIG-IP APM systems by midnight on Monday, March 30, 2026, escal...
CISA KEV patch directive for CVE-2025-53521
Advisory/Mitigation
H score86
First: 30.03.2026 10:07
Last: 30.03.2026 10:07
Sources 1
About this happening:
CISA added CVE-2025-53521 to its KEV catalog and told federal agencies to patch the F5 BIG-IP flaw within three days. The directive is urgent because the bug is be...
CISA KEV patch directive for CVE-2025-53521
Advisory/MitigationAbout this happening: CISA added CVE-2025-53521 to its KEV catalog and told federal agencies to patch the F5 BIG-IP flaw within three days. The directive is urgent because the bug is be...
Ivanti EPMM exploitation wave (CVE-2026-1281)
Exploitation Wave
H score64
First: 12.02.2026 09:32
Last: 12.02.2026 09:32
Sources 1
About this happening:
Ivanti Endpoint Manager Mobile (EPMM) is facing an active exploitation wave against CVE-2026-1281 and CVE-2026-1340, creating immediate risk for internet-facing ma...
Ivanti EPMM exploitation wave (CVE-2026-1281)
Exploitation WaveAbout this happening: Ivanti Endpoint Manager Mobile (EPMM) is facing an active exploitation wave against CVE-2026-1281 and CVE-2026-1340, creating immediate risk for internet-facing ma...
Timeline
-
23.09.2026 10:17 2 articles · 0h ago
F5 BIG-IP APM zero-day RCE (CVE-2026-94127)
Initial DisclosureF5 disclosed that CVE-2026-94127 is a BIG-IP APM zero-day being exploited in remote code execution attacks on OAuth Authorization Server deployments. The company released security updates and a temporary iRule mitigation for systems that cannot be patched immediately.
Show sources
- F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks — www.bleepingcomputer.com — 23.09.2026 10:17
- F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks — www.bleepingcomputer.com — 23.09.2026 10:17