F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Summary

Attackers are actively exploiting a critical vulnerability in F5 BIG-IP Access Policy Manager (APM) that allows for unauthenticated remote code execution. The flaw, CVE-2026-94127, specifically impacts systems configured as OAuth authorization servers and has been patched by F5 with engineering hotfixes.

IFF Assessment

FOE

This article details a critical vulnerability that allows for unauthenticated remote code execution, posing a significant threat to organizations using the affected F5 BIG-IP APM product.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 25, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching F5 BIG-IP APM instances, particularly those acting as OAuth authorization servers, to mitigate the risk of unauthenticated RCE. Continuous monitoring for indicators of compromise related to this vulnerability is crucial.

Read Full Story →