Exploited in the wild BIG-IP Access Policy Manager network-edge F5 zero-day
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
CVE Tools coverage
F5 has released engineering hotfixes for CVE-2026-94127, an exploited heap-based buffer overflow in BIG-IP Access Policy Manager when it operates as an OAuth authorization server. Unauthenticated attackers can send crafted traffic to an affected virtual server and execute code; impacted releases are 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 before their respective hotfixes. Organizations should install the applicable F5 hotfix, or obtain F5's iRule mitigation while investigating for compromise.