F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Cybersecurity · September 24, 2026

Cybersecurity·thehackernews.com

F5 has confirmed active exploitation of CVE-2026-94127, a critical, unauthenticated remote code execution flaw in BIG-IP Access Policy Manager. The bug only affects deployments where APM issues OAuth access tokens to applications, and F5 published an advisory with engineering hotfixes on September 22. Organizations running APM as an OAuth authorization server should apply the fix immediately given confirmed in-the-wild attacks.

// source: thehackernews.com ↗

← Back to Blog