Critical BIG-IP gateway flaw exposes hospital remote access

F5 has pushed emergency patches for a zero-day that lets an unauthenticated attacker run code on BIG-IP APM, a gateway common in clinical remote access.

MedRisk Staff
By
2 Min Read

An unauthenticated attacker can run code on a widely deployed F5 access gateway, and the zero-day is already being used in the wild.

F5 issued emergency updates for the flaw, tracked as CVE-2026-94127 and scored 9.8. The exposure hinges on a specific setup, where an access policy and an OAuth profile share a virtual server. The exception covers shops that run APM purely as an OAuth client or resource server, with no authorization-server profile in place.

That distinction matters for healthcare networks, where BIG-IP Access Policy Manager is a familiar appliance. Hospitals lean on it to broker clinician remote access, VPN sessions, and single sign-on into electronic health records and patient portals. A gateway in that spot is a high-value target: a foothold can expose the sessions and traffic moving behind it, and downtime can cut staff off from the systems they need at the bedside.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, setting a September 25, 2026 remediation deadline for federal agencies. The same product is exposed regardless of who runs it, which makes the deadline a sensible target for everyone.

Healthcare teams should inventory BIG-IP APM instances, determine whether an OAuth Authorization Server profile is configured, apply the vendor’s emergency fix, and look for signs of follow-on activity.

Share This Article