F5's Authentication Appliance Is Under Active Attack and Shares Are Up 75% Anyway
CISA gave federal agencies three days to patch an exploited zero-day in BIG-IP APM, F5's flagship login product. The market's only markdown that week was the forecast.
Vincent Jiang · 3 min read
F5 told customers on 22 September that attackers are exploiting a hole in its flagship login appliance. CVE-2026-94127, a heap-based buffer overflow in BIG-IP APM running as an OAuth Authorization Server, hands an unauthenticated attacker remote code execution and is scored 9.8 under CVSS v3.1 12. CISA listed it as known-exploited the same day and gave federal agencies until Friday, forensic triage required under BOD 26-04 3.
The flaw sits in the machine that checks every login
APM is the centralized proxy that secures access to enterprise networks, applications, cloud services and APIs 4. Versions 21.1.0, 17.5.0 to 17.5.1 and 17.1.0 to 17.1.3 are exposed, appliance mode included, through the data plane; F5 found the bug internally and shipped hotfixes, with a mitigation iRule for slow patchers 1. Shadowserver counts more than 14,700 internet-facing APM addresses and cannot say how many are patched or honeypots 4. The attack tell is repeated OAuth failures, then suspicious commands, then a traffic-management crash 1. Who pays: the enterprises and agencies behind those addresses, pushed by CISA's deadline into patching and forensic triage 34. Who gets paid: holders of the premium, until a victim is named.
The market's only markdown was the forecast
Fiscal third-quarter revenue hit $865.1 million, up 11 percent, with adjusted EPS of $4.73 against a $3.98 consensus 5.
Margins held in the low 80s through the quarter before the zero-day
- Gross margin
- Operating margin
Data
| Gross margin | Operating margin | |
|---|---|---|
| Q3 '24 | 80.8% | 25.6% |
| Q4 '24 | 81.7% | 26.8% |
| Q1 '25 | 80.7% | 21.7% |
| Q2 '25 | 81% | 25.2% |
| Q3 '25 | 82.2% | 25.4% |
| Q4 '25 | 81.5% | 26% |
| Q1 '26 | 81.4% | 22.1% |
| Q2 '26 | 82.2% | 24.7% |
F5's biggest quarter in eight closed three months before the APM zero-day
Data
| F5 revenue | |
|---|---|
| Q3 '24 | $746.67M |
| Q4 '24 | $766.49M |
| Q1 '25 | $731.12M |
| Q2 '25 | $780.37M |
| Q3 '25 | $810.09M |
| Q4 '25 | $822.47M |
| Q1 '26 | $811.7M |
| Q2 '26 | $865.08M |
Three days after the advisory, an investor note credited the stock's 75 percent year-to-date gain to AI-security demand and institutional inflows, without mentioning the flaw 6. The week's one verified down move, a 2.07 percent after-hours drop to $446.55 on 24 September, was framed around raised guidance and a sharpened AI-security strategy; that write-up never mentions the CVE either 7.
A nation-state already walked out with F5's zero-day notes
A year earlier, F5 disclosed that a nation-state actor held long-term access to its BIG-IP product development environment and left with source code and details of undisclosed vulnerabilities 8; the Justice Department allowed F5 to delay that disclosure 9. At the time, F5 said it had no knowledge of undisclosed critical or remote-code flaws among the stolen files 8, and this week's advisory does not connect the new bug to the theft 1. F5 has not said how many systems the current campaign has compromised 9. Since November 2021, CISA has flagged eight exploited F5 flaws, four of them used in ransomware 4.
Growth is real; the tail is unpriced
Exploited zero-days at network vendors are routine now; Check Point and Arista joined the KEV list the same day 3. F5's post-breach containment was validated by NCC Group and IOActive, and CrowdStrike's Falcon EDR ships inside BIG-IP free through 14 October 2026 8. Nothing public this week, least of all the AI-security bull note, priced the fact that the moat and the attack surface ship in the same box 6. Watch for victims named out of the KEV triage, and for the fourth quarter against the $870 to 890 million revenue guide 5.
How this brief was made
01Gathered & sourced291 channels · 1,214 articles▾
Agents swept 291 channels and ingested 1,214 articles, then de-duplicated and ranked them for signal.
02Verified & cross-validated10 claims · 10 data feeds▾
Every one of 10 load-bearing claims was checked against primary sources, with 10 live data feeds reconciling the figures and charts.
- 1F5, K000162605: BIG-IP APM vulnerability CVE-2026-94127, 22 September 2026
- 2SecurityWeek, Critical F5 BIG-IP Vulnerability Exploited as Zero-Day, 23 September 2026
- 3CISA, Known Exploited Vulnerabilities Catalog (F5 BIG-IP APM, CVE-2026-94127, added 22 September 2026, due 25 September 2026), retrieved 27 September 2026
- 4BleepingComputer, F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks, 23 September 2026
- 5WTOP / Associated Press, F5: Fiscal Q3 Earnings Snapshot, 27 July 2026
- 6Yahoo Finance / MoneyFlows, AI Security, Institutional Inflows Push F5 Shares Up 75% YTD, 25 September 2026
- 7AD HOC NEWS, F5 stock falls 2.07 percent as guidance resets the bar, 24 September 2026
- 8F5, K000154696: F5 Security Incident, 15 October 2025, updated 22 October 2025
- 9The Register, Someone's attacking a critical 0-day RCE in F5 BIG-IP APM, 23 September 2026
- 10Sharadar quarterly fundamentals from F5's SEC filings, retrieved 27 September 2026
03Reviewed & edited1 human editor▾
One editor read the draft against the evidence, tuned the framing, and signed off before it shipped.
Become a contributor
Reporting on the business of AI and want it read? We take pitches from outside contributors who bring primary sources and a number worth arguing about.
Deepdive
AI-generated from this story and its cited sources. Not investment advice.



