F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Summary
Attackers are actively exploiting a critical vulnerability in F5 BIG-IP Access Policy Manager (APM) that allows for unauthenticated remote code execution. The flaw, CVE-2026-94127, specifically impacts systems configured as OAuth authorization servers and has been patched by F5 with engineering hotfixes.
IFF Assessment
This article details a critical vulnerability that allows for unauthenticated remote code execution, posing a significant threat to organizations using the affected F5 BIG-IP APM product.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 25, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should prioritize patching F5 BIG-IP APM instances, particularly those acting as OAuth authorization servers, to mitigate the risk of unauthenticated RCE. Continuous monitoring for indicators of compromise related to this vulnerability is crucial.