F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5…

security

Sources

Vulnerabilities

Why this score
Signals contributing to the severity score
SignalPoints
kev added50
kev short fuse — 3 days to remediate15
public poc — 1 repositories20