CVE Tools

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedBIG-IP Access Policy Manager

Our summary

F5 released fixes for CVE-2026-94127, an actively exploited remote code execution zero-day in BIG-IP Access Policy Manager. The issue affects BIG-IP APM virtual servers configured with both an access policy and OAuth profile when operating as an OAuth Authorization Server; OAuth Client or Resource Server-only deployments are not affected.

CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog. Organizations should install F5's updates, investigate OAuth authentication failures, suspicious commands, and subsequent TMM SIGABRT events, or apply F5's iRule mitigation where patching is delayed.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store