F5 has issued security updates for a critical zero-day in BIG-IP APM, which is being actively exploited in remote code execution attacks when specific OAuth authorization server settings are enabled. CISA has added CVE-2026-94127 to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch the flaw promptly. #F5 #BIG-IPAPM #CVE202694127 #CISA
Keypoints
- F5 patched a critical BIG-IP APM zero-day vulnerability.
- The flaw is tracked as CVE-2026-94127.
- It can lead to remote code execution on affected systems.
- Only deployments with an OAuth authorization server profile are impacted.
- CISA added the vulnerability to its KEV Catalog and urged rapid patching.