F5 fixes actively exploited BIG-IP APM zero-day, CVE-2026-94127
F5 issued patches for a critical zero-day in its BIG-IP Access Policy Manager, tracked as CVE-2026-94127, which is being exploited to achieve remote code execution on systems configured as an OAuth Authorization Server. F5 says setups using APM only as an OAuth Client or Resource Server are unaffected, and offered an iRule-based mitigation for those unable to patch immediately. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and directed federal agencies to remediate it by Friday.