F5 BIG-IP APM flaw added to US 'actively exploited' list — here's what's actually known
CISA says CVE-2026-94127 is being used in the wild against F5's BIG-IP Access Policy Manager, but the public record is short on the how and who.
A vulnerability in F5’s BIG-IP Access Policy Manager (APM) has been added to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalogue, meaning it isn’t a theoretical bug sitting in a lab somewhere — CISA’s listing states plainly that it is being exploited right now.
The entry, tracked as CVE-2026-94127, was added on 22 September 2026. US federal civilian agencies have been given until 25 September to patch or mitigate it, a notably tight three-day turnaround that CISA reserves for flaws it considers genuinely dangerous.
What’s actually confirmed
Here’s the honest state of play: CISA’s KEV catalogue confirms the vendor (F5), the product (BIG-IP APM), the date it was added, and the compliance deadline for federal agencies. It also confirms exploitation is happening, not hypothetical. Whether ransomware gangs are involved is, per CISA’s own listing, currently marked “unknown”.
What isn’t in the public record yet — at least not in the sources checked for this story — is the technical nitty-gritty: what kind of flaw this is (remote code execution, authentication bypass, privilege escalation, or something else), how difficult it is to exploit, or how many organisations have been hit so far. Neither the CISA catalogue nor the NVD entry linked from it lay out a plain-English description of the bug’s mechanics in the material available. If you’re after that level of detail, F5’s own security advisory is the place to watch, though it isn’t among the sources we’ve verified for this piece.
So who is actually at risk
BIG-IP APM is not something you’ll find on a home router or a games console. It’s an enterprise-grade access management appliance — the kind of kit large organisations, government departments and service providers use to control who gets into their networks and applications. If you’re an ordinary reader with a laptop and a home broadband connection, this bug has nothing to do with you directly.
The people who need to pay attention are IT and security teams at organisations running BIG-IP APM, particularly anyone in or contracting for the US federal government, where CISA’s Binding Operational Directive process makes patching mandatory by the stated deadline. UK organisations aren’t bound by that directive, but CISA’s KEV list is widely treated as an early-warning signal across the industry, since it only includes flaws with confirmed real-world exploitation rather than speculative risk scores.
What to do about it
If your organisation runs F5 BIG-IP APM, the sensible move is to check F5’s advisory for this CVE, apply whatever patch or mitigation the vendor has issued, and follow CISA’s general guidance on prioritising updates by risk rather than assuming this can wait for a routine maintenance window. If you don’t manage F5 infrastructure, there’s genuinely nothing to do here — this isn’t a consumer-facing issue and no home devices are implicated.
The bigger picture is one we’ve flagged before: KEV listings are a useful shorthand for “this is being actively abused, take it seriously”, but they’re not a substitute for reading the actual vendor advisory before deciding how urgently to act. Right now, the confirmed facts are the CVE number, the product, and the deadline — everything else about how it’s being exploited is, for now, still filling in.