F5's BIG-IP Flaw Was Already Being Exploited Before a Patch Existed
A critical security hole in widely used network hardware is under active attack. Federal agencies have three days to patch. Here's what the flaw does and who is at risk.

Key points
- US federal agencies face a mandatory patch deadline of 25 September 2026, one of the shortest windows CISA has ever imposed.
- The flaw scores 9.8 out of 10 on the standard severity scale and lets attackers run any code they choose on a vulnerable device, without a password.
- Only deployments where BIG-IP APM is set up as an OAuth Authorization Server (a specific identity-checking role) are vulnerable; OAuth Client and Resource Server setups are not affected.
- F5 discovered the bug internally and confirmed it is being exploited in the wild before a patch was publicly available, making it a zero-day.
F5 BIG-IP APM is hardware and software that large organisations use to control who can access their internal applications. Think of it as a gatekeeper standing between the internet and a company's private systems. That gatekeeper has a hole in it.
An attacker can send the device a carefully crafted packet of data, crash its memory boundary, and plant malicious software on the machine. No login required.
The attack works only when BIG-IP APM has an access policy active alongside an OAuth Authorization Server profile, a role where the device issues digital tokens confirming a user's identity to other services. Organisations running BIG-IP APM purely as an OAuth Client or Resource Server aren't in the firing line. The authorization-server role is common in large enterprise networks, which is precisely what makes this dangerous. We first covered active threats targeting F5 BIG-IP devices on 17 September, when researchers detailed a memory-resident rootkit hooking into the same class of appliance.
How bad is this, really?
Bad enough that the US Cybersecurity and Infrastructure Security Agency (CISA, the federal body that tracks and responds to cyber threats) added the flaw to its Known Exploited Vulnerabilities catalogue the same day F5 published its advisory. That catalogue lists flaws criminals are actively using right now, not theoretically. Federal agencies must patch within three days of a KEV listing under a standing directive called BOD 26-04.
Three days is a short window. It signals CISA believes exploitation is widespread or accelerating. We saw the same three-day pressure applied just days earlier for a WSO2 vulnerability.
F5 confirmed it found the bug through internal research and discovered exploitation before issuing a fix, meeting the definition of a zero-day. The company has since released hotfixes for affected versions.
| Affected version | Status |
|---|---|
| 21.1.0 | Hotfix available |
| 17.5.0 to 17.5.1 | Hotfix available |
| 17.1.0 to 17.1.3 | Hotfix available |
F5 also notes that the BIG-IP system in Appliance mode is vulnerable, and that this is a data-plane issue. The attack targets the path through which normal traffic flows, not the administrative control panel, so the usual advice of restricting management access doesn't protect you here.
F5 published three indicators of compromise (specific warning signs that an attack may have occurred) in its advisory. Security teams should correlate all three together; any one alone could be a false alarm.
My read: the confirmed zero-day status combined with a three-day federal deadline is what matters here. The CVSS score is almost beside the point. Organisations treating this as a routine patch cycle are miscalibrated.
Should ordinary people be worried?
Directly, no. Home users don't run F5 BIG-IP hardware. If you use online services managed by large employers or financial institutions, though, their internal teams need to act fast. A compromised authorization server could let an attacker move deeper into internal networks.
If you manage IT for an organisation and BIG-IP APM is in your environment, check your OAuth configuration now, apply the hotfix, then cross-reference F5's published indicators of compromise against your logs.
SecurityWeek first reported F5's advisory alongside the CISA listing.



