F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
F5 released fixes for CVE-2026-94127, an actively exploited remote code execution zero-day in BIG-IP Access Policy Manager. The issue affects BIG-IP APM virtual servers configured with both an access policy and OAuth profile when operating as an OAuth Authorization Server; OAuth Client or Resource Server-only deployments are not affected.
CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog. Organizations should install F5's updates, investigate OAuth authentication failures, suspicious commands, and subsequent TMM SIGABRT events, or apply F5's iRule mitigation where patching is delayed.