Summary
F5 has released an emergency patch for CVE-2026-41557, a critical unauthenticated remote code execution zero-day vulnerability in BIG-IP Access Policy Manager that was being actively exploited in attacks against financial services and government organizations before the patch was available. The vulnerability is rated CVSS 9.8 and exists in the way BIG-IP APM parses session tokens during the authentication negotiation phase. An unauthenticated attacker who can reach the BIG-IP APM management interface or virtual server can send a malformed session token that triggers a stack-based buffer overflow, achieving arbitrary code execution with root privileges. CISA has added CVE-2026-41557 to its Known Exploited Vulnerabilities catalog with a September 25, 2026 federal remediation deadline.
Timeline
| Date | Event |
|---|---|
| Prior to Sep 22, 2026 | CVE-2026-41557 exploited as zero-day in attacks against financial and government organizations |
| Sep 22, 2026 | F5 releases emergency patch for BIG-IP APM; discloses CVE-2026-41557 and confirms active exploitation |
| Sep 22-23, 2026 | CISA adds CVE-2026-41557 to KEV catalog; sets September 25 federal remediation deadline |
What Happened
BIG-IP Access Policy Manager is F5’s remote access and authentication gateway platform, widely deployed in enterprise, financial, and government environments as the entry point for secure remote access, SSL VPN, and application access control. It is an internet-facing device by design, making the attack surface for CVE-2026-41557 broad.
CVE-2026-41557 is a stack-based buffer overflow in the session token parsing logic of BIG-IP APM’s authentication negotiation handler. The token parser does not adequately validate the length or structure of the submitted token, allowing an attacker to submit a malformed token that overflows a fixed-size stack buffer and redirects execution to attacker-controlled code running with root privileges on the BIG-IP operating system.
F5 has published indicators of compromise including anomalous authentication log entries and unexpected outbound connections from BIG-IP appliances. Organizations should apply the emergency patch immediately, review BIG-IP APM logs for exploitation attempts, and treat any internet-exposed BIG-IP APM appliance running a vulnerable version as potentially compromised pending forensic triage.
Domain Intelligence
f5.com — 61.81
f5.com scores in the low-trust range at 61.81. F5 is the vendor of the affected BIG-IP Access Policy Manager product and the party that patched CVE-2026-41557 and published remediation guidance. One threat intelligence source has flagged f5.com but the observation has not been independently corroborated.
The Trust Observatory · thetrustobservatory.com · September 23, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026