F5 BIG-IP APM RCE exploited in the wild
CERT-FR warns of an actively exploited remote code execution vulnerability (CVE-2026-94127) in F5 BIG-IP APM.
CERT-FR has published an advisory concerning a remote code execution vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability, tracked as CVE-2026-94127, allows an attacker to achieve arbitrary code execution on affected systems. F5 has confirmed that the vulnerability is being actively exploited in the wild, making this an urgent patching priority for organizations running affected BIG-IP APM versions.
Affected versions include BIG-IP APM 17.1.x prior to 17.1.3 (without hotfix Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso), 17.5.x prior to 17.5.1 (without hotfix Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso), and 21.x prior to 21.1.0 (without hotfix Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso). F5 has released indicators of compromise in its own security bulletin (K000162605) to help defenders identify exploitation attempts or successful compromise.
Defenders running BIG-IP APM should apply the vendor hotfixes immediately given confirmed active exploitation, and review the F5 bulletin for the referenced indicators of compromise to hunt for signs of prior compromise on their systems.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1220
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free