Back to Blog

Your VPN could be hijacked – critical F5 BIG‑IP bug exploited

Your VPN could be hijacked – critical F5 BIG‑IP bug exploited
September 24, 2026|David Velarde RoblesDavid Velarde Robles

Why you should read this now

If your business relies on a VPN or single‑sign‑on (SSO) solution that runs on F5 BIG‑IP Access Policy Manager (APM), a critical vulnerability is being actively exploited. Attackers can take control of the remote‑access gateway and move laterally inside your network. The good news: a patch is already available. The urgent news: you need to apply it today, or you risk a breach that could shut down operations, expose customer data, and damage your reputation.

Critical F5 BIG‑IP bug (CVE‑2026‑94127) – what happened

  • The flaw – CVE‑2026‑94127 is a heap‑based buffer overflow (a coding error that lets attackers write malicious data into memory) in BIG‑IP APM when it is configured as an OAuth authorization server with an access policy and OAuth profile on the same virtual server.
  • Severity – The vulnerability scores 9.3 out of 10 on the CVSS v4.0 scale, classifying it as critical.
  • Active exploitation – Both F5 and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have confirmed that attackers are already using the flaw to execute arbitrary code on vulnerable devices.
  • Patch released – F5 published a security update on Tuesday that fixes the buffer overflow. CISA added the issue to its Known Exploited Vulnerabilities catalog and gave federal agencies a deadline to patch by Friday.

In short, the bug lets a remote attacker bypass the authentication checks that protect your VPN or SSO portal, potentially giving them unrestricted access to your internal applications and data.

Why it matters to your business

Many small and medium‑size businesses use F5 BIG‑IP APM as the single point of entry for remote workers, partners, and cloud services. If that entry point is compromised:

How to protect your business from hackers

  1. Network takeover – Attackers can move from the VPN into internal systems, stealing data or deploying ransomware.
  2. Service disruption – A compromised gateway can be taken offline, cutting off remote access for all employees.
  3. Compliance risk – Data breaches may breach GDPR or other regulations, leading to fines and loss of customer trust.

Because the vulnerability is being exploited in the wild, waiting for “just in case” is not an option. The window to protect yourself is now.

Immediate actions you can take

1. Apply the F5 patch today

  • Download the latest BIG‑IP APM update from the F5 support portal.
  • Backup your configuration before installing the patch.
  • Schedule a short maintenance window (5‑10 minutes) to apply the update and reboot if required.

If you are not comfortable performing the update yourself, consider engaging a trusted IT partner to do it for you.

2. Verify your OAuth/SSO settings

  • Ensure that the OAuth authorization server and the access policy are not sharing the same virtual server.
  • Review all OAuth client configurations for unnecessary scopes or overly permissive redirects.

3. Enable multi‑factor authentication (MFA)

  • Add an extra verification step (e.g., a code sent to a phone) for all VPN and SSO logins.
  • MFA dramatically reduces the chance that a stolen credential can be used to exploit the bug.

4. Strengthen monitoring and alerts

  • Activate logging on the BIG‑IP APM device and forward logs to a security information and event management (SIEM) system or a cloud‑based log service.
  • Set up alerts for unusual login patterns, such as multiple failed attempts or logins from unexpected locations.

5. Test your remote‑access flow

  • After patching, run a quick test: connect from an external device, verify that authentication works, and confirm that no unexpected redirects occur.
  • Document the steps and keep the test results for future reference.

Frequently asked questions

Q: My business only uses the VPN for a few employees. Do I still need to patch?
A: Yes. Even a single compromised VPN account can give an attacker a foothold inside your network. The risk is proportional to the value of the data you store, not the number of users.

Q: We don’t manage the F5 device ourselves – it’s hosted by a provider. What should we do?
A: Contact your provider immediately and ask for confirmation that the patch has been applied. Request a written statement or a change‑log entry showing the update.

Q: Can I just disable the OAuth feature until the patch is installed?
A: Disabling the vulnerable component is a temporary mitigation, but it may break your SSO flow. If you choose this route, make sure you have an alternative authentication method in place and re‑enable the feature only after the patch is applied.

Q: How quickly should I patch the critical F5 BIG‑IP bug?
A: As soon as possible – the vulnerability is already being exploited in the wild, so apply the patch today and verify the update.

How IT Move NL can help

If you’d like a hand with the patch rollout or a quick security health check, just drop us a line – we’ll take care of the technical details so you can keep focusing on your business.


Sources:

David Velarde Robles
David Velarde Robles

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent

Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.

>

STAY IN THE LOOP

// Cloud, AI & DevOps insights — straight to your inbox.

>

No spam. Unsubscribe anytime.

Share this article:

Need help with your cloud infrastructure?

Our team of experts is ready to help you navigate the complexities of modern cloud architecture.

Get in Touch