TTO-2026-0923-155 · September 23, 2026 Zero-DayActive Exploitation

F5 BIG-IP APM Zero-Day CVE-2026-41557 Exploited in Remote Code Execution Attacks Against Financial and Government Sectors

f5.comCVE-2026-41557 CVSS 9.8BIG-IP Access Policy ManagerUnauthenticated RCE via session token parsingFinancial and government sector targetingCISA KEV September 25 deadline

Summary

F5 has released an emergency patch for CVE-2026-41557, a critical unauthenticated remote code execution zero-day vulnerability in BIG-IP Access Policy Manager that was being actively exploited in attacks against financial services and government organizations before the patch was available. The vulnerability is rated CVSS 9.8 and exists in the way BIG-IP APM parses session tokens during the authentication negotiation phase. An unauthenticated attacker who can reach the BIG-IP APM management interface or virtual server can send a malformed session token that triggers a stack-based buffer overflow, achieving arbitrary code execution with root privileges. CISA has added CVE-2026-41557 to its Known Exploited Vulnerabilities catalog with a September 25, 2026 federal remediation deadline.

Timeline

DateEvent
Prior to Sep 22, 2026CVE-2026-41557 exploited as zero-day in attacks against financial and government organizations
Sep 22, 2026F5 releases emergency patch for BIG-IP APM; discloses CVE-2026-41557 and confirms active exploitation
Sep 22-23, 2026CISA adds CVE-2026-41557 to KEV catalog; sets September 25 federal remediation deadline

What Happened

BIG-IP Access Policy Manager is F5’s remote access and authentication gateway platform, widely deployed in enterprise, financial, and government environments as the entry point for secure remote access, SSL VPN, and application access control. It is an internet-facing device by design, making the attack surface for CVE-2026-41557 broad.

CVE-2026-41557 is a stack-based buffer overflow in the session token parsing logic of BIG-IP APM’s authentication negotiation handler. The token parser does not adequately validate the length or structure of the submitted token, allowing an attacker to submit a malformed token that overflows a fixed-size stack buffer and redirects execution to attacker-controlled code running with root privileges on the BIG-IP operating system.

F5 has published indicators of compromise including anomalous authentication log entries and unexpected outbound connections from BIG-IP appliances. Organizations should apply the emergency patch immediately, review BIG-IP APM logs for exploitation attempts, and treat any internet-exposed BIG-IP APM appliance running a vulnerable version as potentially compromised pending forensic triage.

Domain Intelligence

f5.com — 61.81

f5.com scores in the low-trust range at 61.81. F5 is the vendor of the affected BIG-IP Access Policy Manager product and the party that patched CVE-2026-41557 and published remediation guidance. One threat intelligence source has flagged f5.com but the observation has not been independently corroborated.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 23, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026