F5 and CISA warned that a critical BIG-IP Access Policy Manager (APM) flaw, tracked as CVE-2026-94127, has been exploited as a zero-day to enable unauthenticated remote code execution. The vulnerability affects specific BIG-IP APM configurations, and F5 has released hotfixes while CISA added the issue to its Known Exploited Vulnerabilities list. #F5 #BIGIPAPM #CVE202694127 #CISA
Keypoints
- CVE-2026-94127 is a critical BIG-IP APM vulnerability with a CVSS score of 9.8.
- The flaw can be exploited through malicious traffic when APM and an OAuth profile are configured on a virtual server.
- Unauthenticated attackers can use the bug to achieve remote code execution.
- The issue affects only specific BIG-IP APM deployments, including OAuth Authorization Server configurations and Appliance mode.
- F5 released hotfixes, and CISA added the vulnerability to its KEV list for urgent patching.
Read More: https://www.securityweek.com/critical-f5-big-ip-vulnerability-exploited-as-zero-day/