F5's Authentication Appliance Is Under Active Attack and Shares Are Up 75% Anyway

CISA gave federal agencies three days to patch an exploited zero-day in BIG-IP APM, F5's flagship login product. The market's only markdown that week was the forecast.

In this storyCRWD
Vincent JiangVincent Jiang · 3 min read
Share
F5 Tower, the glass skyscraper that is F5's headquarters in downtown Seattle, seen from street level
1 / 6Slide 1 of 6
F5 Tower in downtown Seattle, the company's headquarters. Shares are up 75 percent this year even as its flagship login appliance is under active attack.

F5 told customers on 22 September that attackers are exploiting a hole in its flagship login appliance. CVE-2026-94127, a heap-based buffer overflow in BIG-IP APM running as an OAuth Authorization Server, hands an unauthenticated attacker remote code execution and is scored 9.8 under CVSS v3.1 12. CISA listed it as known-exploited the same day and gave federal agencies until Friday, forensic triage required under BOD 26-04 3.

The flaw sits in the machine that checks every login

APM is the centralized proxy that secures access to enterprise networks, applications, cloud services and APIs 4. Versions 21.1.0, 17.5.0 to 17.5.1 and 17.1.0 to 17.1.3 are exposed, appliance mode included, through the data plane; F5 found the bug internally and shipped hotfixes, with a mitigation iRule for slow patchers 1. Shadowserver counts more than 14,700 internet-facing APM addresses and cannot say how many are patched or honeypots 4. The attack tell is repeated OAuth failures, then suspicious commands, then a traffic-management crash 1. Who pays: the enterprises and agencies behind those addresses, pushed by CISA's deadline into patching and forensic triage 34. Who gets paid: holders of the premium, until a victim is named.

The market's only markdown was the forecast

Fiscal third-quarter revenue hit $865.1 million, up 11 percent, with adjusted EPS of $4.73 against a $3.98 consensus 5.

Margins held in the low 80s through the quarter before the zero-day

  • Gross margin
  • Operating margin
0%50%100%Q3 '24Q4 '24Q1 '25Q2 '25Q3 '25Q4 '25Q1 '26Q2 '2682.2%
Data
Gross marginOperating margin
Q3 '2480.8%25.6%
Q4 '2481.7%26.8%
Q1 '2580.7%21.7%
Q2 '2581%25.2%
Q3 '2582.2%25.4%
Q4 '2581.5%26%
Q1 '2681.4%22.1%
Q2 '2682.2%24.7%
Gross and operating margin, percent of revenue, calendar-labelled quarters. Source: Sharadar quarterly fundamentals from F5's SEC filings, retrieved 27 September 2026.10

F5's biggest quarter in eight closed three months before the APM zero-day

$700M$750M$800M$850M$900MQ3 '24Q4 '24Q1 '25Q2 '25Q3 '25Q4 '25Q1 '26Q2 '26APM zero-day disclosed after thisquarter closed
Data
F5 revenue
Q3 '24$746.67M
Q4 '24$766.49M
Q1 '25$731.12M
Q2 '25$780.37M
Q3 '25$810.09M
Q4 '25$822.47M
Q1 '26$811.7M
Q2 '26$865.08M
Quarterly revenue, US$ millions, calendar-labelled quarters; F5's fiscal Q3 2026 ended 30 June 2026. Source: Sharadar quarterly fundamentals from F5's SEC filings, retrieved 27 September 2026.10

Three days after the advisory, an investor note credited the stock's 75 percent year-to-date gain to AI-security demand and institutional inflows, without mentioning the flaw 6. The week's one verified down move, a 2.07 percent after-hours drop to $446.55 on 24 September, was framed around raised guidance and a sharpened AI-security strategy; that write-up never mentions the CVE either 7.

A nation-state already walked out with F5's zero-day notes

A year earlier, F5 disclosed that a nation-state actor held long-term access to its BIG-IP product development environment and left with source code and details of undisclosed vulnerabilities 8; the Justice Department allowed F5 to delay that disclosure 9. At the time, F5 said it had no knowledge of undisclosed critical or remote-code flaws among the stolen files 8, and this week's advisory does not connect the new bug to the theft 1. F5 has not said how many systems the current campaign has compromised 9. Since November 2021, CISA has flagged eight exploited F5 flaws, four of them used in ransomware 4.

Growth is real; the tail is unpriced

Exploited zero-days at network vendors are routine now; Check Point and Arista joined the KEV list the same day 3. F5's post-breach containment was validated by NCC Group and IOActive, and CrowdStrike's Falcon EDR ships inside BIG-IP free through 14 October 2026 8. Nothing public this week, least of all the AI-security bull note, priced the fact that the moat and the attack surface ship in the same box 6. Watch for victims named out of the KEV triage, and for the fourth quarter against the $870 to 890 million revenue guide 5.

How this brief was made

Become a contributor

Reporting on the business of AI and want it read? We take pitches from outside contributors who bring primary sources and a number worth arguing about.

Share

Deepdive

AI-generated from this story and its cited sources. Not investment advice.

Reader comments

0 comments

    Sign up

    Get your curated digest

    After email confirmation, you will receive a daily digest of the most relevant news that matter to your portfolio