CVE Tools

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

SecurityWeekBy Ionut Arghire

Reported exploitedBIG-IP Access Policy Manager

Our summary

F5 has confirmed active zero-day exploitation of CVE-2026-94127, a CVSS 9.8 vulnerability in BIG-IP Access Policy Manager. Unauthenticated attackers can execute code remotely when a vulnerable BIG-IP APM deployment is configured as an OAuth Authorization Server with an access policy and OAuth profile on a virtual server.

Affected releases are BIG-IP APM 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3; F5 has issued hotfixes. CISA has also added the flaw to its Known Exploited Vulnerabilities catalog, making prompt remediation important.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store