F5 patches exploited BIG-IP APM zero-day enabling RCE
F5 released emergency fixes for CVE-2026-94127 (CVSS 9.8) in BIG-IP Access Policy Manager, which lets unauthenticated attackers execute arbitrary code. The flaw is already being exploited in the wild, and CISA added it to its KEV catalog with a September 25, 2026 deadline.
- CVE-2026-94127 carries a CVSS score of 9.8 and allows unauthenticated RCE
- Affected versions: BIG-IP 17.1.0–17.1.3, 17.5.0–17.5.1 and 21.1.0 with APM as OAuth Authorization Server
- CISA added the flaw to its KEV catalog, giving US federal agencies until September 25, 2026
- Shadowserver is tracking over 14,700 IP addresses with BIG-IP APM fingerprints
Read next
Security