F5 has issued emergency security updates to address a critical zero-day vulnerability in its BIG-IP Access Policy Manager (APM) that is already being actively exploited in remote code execution (RCE) attacks. The flaw, tracked as CVE-2026-94127, carries a maximum severity CVSS score of 9.8, highlighting the extreme risk it poses to unpatched systems.

According to an advisory reported by Security Affairs, the vulnerability allows a remote, unauthenticated attacker to execute arbitrary code on affected BIG-IP APM devices. This combination of high severity and ease of exploitation places the patch at the highest level of urgency for network administrators.

BIG-IP APM appliances are commonly deployed at the network edge, handling critical authentication and VPN traffic for enterprise networks. This privileged position means a compromised APM could serve as a gateway for attackers to infiltrate an entire corporate network, rather than causing damage limited to a single device. The active exploitation of this zero-day makes immediate patching imperative for any organization using the affected software.

F5 has released patches for impacted versions of the software. The company is urging all customers to implement the security updates immediately. For organizations that cannot apply the patch right away, interim mitigations are recommended, such as restricting management interface access to trusted networks only to reduce the attack surface.

This incident underscores the persistent threat targeting critical network infrastructure. Administrators managing F5 environments are advised to consult F5's official advisory for the complete list of affected and patched versions, as well as to hunt for indicators of compromise (IOCs) associated with this active campaign. The urgency of this alert cannot be overstated; proactive measures are essential to defend against this readily exploitable flaw.


F5 已發布緊急安全更新,以解決其 BIG-IP 存取策略管理器 (APM) 中一個正遭積極利用的嚴重零日漏洞。該漏洞編號為 CVE-2026-94127,CVSS 嚴重性評分達最高級別的 9.8,凸顯了其對未修補系統所帶來的極端風險。

根據 Security Affairs 報導的安全公告,該漏洞允許遠端未經身份驗證的攻擊者在受影響的 BIG-IP APM 設備上執行任意程式碼。此漏洞的高嚴重性及易於利用的特性,令相關補丁成為網絡管理員刻不容緩的最優先處理事項。

BIG-IP APM 裝置通常部署於網絡邊緣,負責處理企業網絡的關鍵身份驗證及 VPN 流量。此特殊地位意味著,遭入侵的 APM 可作為攻擊者滲透整個企業網絡的跳板,造成的損害絕非僅限於單一設備。由於此零日漏洞正遭積極利用,所有使用受影響軟件的組織均須立即進行修補。

F5 已為受影響的軟件版本發布補丁,並敦促所有客戶立即實施安全更新。對於無法即時套用補丁的組織,建議採取臨時緩解措施,例如將管理介面的存取限制於可信網絡內,以縮減攻擊面。

此次事件再次凸顯針對關鍵網絡基礎設施的持續性威脅。管理 F5 環境的管理員應查閱 F5 的官方公告,以獲取受影響及已修補版本的完整清單,並主動偵測與此活躍攻擊活動相關的入侵指標 (IOC)。此警報的緊迫性不容忽視;採取主動防禦措施對於抵禦此易於利用的漏洞至關重要。

新聞來源 / Original News Source