Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
F5 and CISA warned of an actively exploited critical zero-day (CVE-2026-94127) in BIG-IP APM enabling unauthenticated remote code execution.
F5 and CISA have warned that a critical zero-day vulnerability in F5 BIG-IP Access Policy Manager (APM) is being actively exploited. Tracked as CVE-2026-94127 with a CVSS score of 9.8, the flaw allows unauthenticated attackers to achieve remote code execution via malicious traffic when APM is configured as an OAuth Authorization Server. F5 has released hotfixes for affected versions, and CISA has added the CVE to its KEV list, mandating federal agencies patch within three days.
95