F5 fixes actively exploited BIG-IP APM zero-day, CVE-2026-94127
F5 issued patches for a critical zero-day in its BIG-IP Access Policy Manager, tracked as CVE-2026-94127, which is being exploited to achieve remote code execution on systems configured as an OAuth Authorization Server. F5 says setups using APM only as an OAuth Client or Resource Server are unaffected, and offered an iRule-based mitigation for those unable to patch immediately. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and directed federal agencies to remediate it by Friday.
GoKawiil's interpretation of the reporting above, not reported fact.
With over 14,700 internet-exposed BIG-IP APM instances identified by Shadowserver, unpatched systems could offer attackers a wide pool of targets, though it's unclear how many are already secured. CISA's warning that such flaws are a common vector for cybercriminal and state-backed actors suggests organizations relying on BIG-IP for network access control face elevated urgency to patch or apply mitigations quickly.
- F5 patched a critical, actively exploited zero-day (CVE-2026-94127) in BIG-IP APM.
- Only deployments using APM as an OAuth Authorization Server are affected; an iRule mitigation exists for those who can't patch immediately.
- CISA added the flaw to its KEV catalog, giving federal agencies until Friday to remediate it.
Source: bleepingcomputer.com, 2026-09-23
Published there as: “F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.