Cybersecurity · September 24, 2026
F5 has confirmed active exploitation of CVE-2026-94127, a critical, unauthenticated remote code execution flaw in BIG-IP Access Policy Manager. The bug only affects deployments where APM issues OAuth access tokens to applications, and F5 published an advisory with engineering hotfixes on September 22. Organizations running APM as an OAuth authorization server should apply the fix immediately given confirmed in-the-wild attacks.
// source: thehackernews.com ↗