# CISA Directs Federal Agencies to Patch F5 BIG-IP Flaw

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. federal agencies secure networks affected by a critical zero-day vulnerability (CVE-2026-94127) in F5's BIG-IP Access Policy Manager (APM). This flaw, actively exploited for remote code execution when configured as an OAuth Authorization Server with an APM access policy and OAuth profile, requires immediate remediation. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog and set a firm deadline of September 25, 2026, for agencies to apply security patches and mitigate risks. Contractors supporting federal IT environments should urgently assess exposure, deploy updates, and conduct thorough reviews for indicators of compromise to maintain compliance and protect sensitive systems.

- **Why this matters:** Federal procurement professionals must prioritize acquisition and deployment of updated F5 BIG-IP APM software and related cybersecurity services to meet CISA's directive.
- Agencies and contractors should verify patch application status and incorporate vulnerability management into ongoing contract performance requirements.
- This directive underscores the critical role of timely cybersecurity patching in federal IT procurement and risk management strategies.
- Businesses providing cybersecurity solutions and managed services can leverage this urgent need to support federal clients in vulnerability remediation and compliance efforts.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 23, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)
- U.S. federal agencies

### Vendors
- F5 ()

### Sources
- [F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks](https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/amp) - bleepingcomputer.com