Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Reported exploitedBIG-IP Access Policy ManagerOur summary
F5 has confirmed active zero-day exploitation of CVE-2026-94127, a CVSS 9.8 vulnerability in BIG-IP Access Policy Manager. Unauthenticated attackers can execute code remotely when a vulnerable BIG-IP APM deployment is configured as an OAuth Authorization Server with an access policy and OAuth profile on a virtual server.
Affected releases are BIG-IP APM 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3; F5 has issued hotfixes. CISA has also added the flaw to its Known Exploited Vulnerabilities catalog, making prompt remediation important.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.