F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
Attackers are exploiting critical F5 BIG-IP APM zero-day CVE-2026-94127 for unauthenticated remote code execution.
F5 disclosed CVE-2026-94127, a critical flaw scored CVSS 9.8 in BIG-IP Access Policy Manager, which lets an unauthenticated attacker execute arbitrary code when APM is an OAuth Authorization Server with an access policy and OAuth profile on the same virtual server. Affected releases are BIG-IP 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0; hotfixes are out and an iRule is only a temporary mitigation. F5 confirmed in-the-wild exploitation, and CISA added the bug to the KEV catalog with a September 25, 2026 federal deadline. The issue is data-plane only, appliance mode is vulnerable, and Shadowserver sees more than 14,700 BIG-IP APM fingerprints, not a confirmed vulnerable count.