chiprook
← Security
SecuritySeptember 24, 2026, 01:12

F5 patches exploited BIG-IP APM zero-day enabling RCE

F5 released emergency fixes for CVE-2026-94127 (CVSS 9.8) in BIG-IP Access Policy Manager, which lets unauthenticated attackers execute arbitrary code. The flaw is already being exploited in the wild, and CISA added it to its KEV catalog with a September 25, 2026 deadline.

F5 patches exploited BIG-IP APM zero-day enabling RCE
#F5#BIG-IP#CISA
Read next
Security

CISA adds Cisco ISE CVE-2026-76460 to exploited vulnerabilities list

Security

Man spent two years hunting fake LinkedIn jobs, got 60,000 removed

Security

Leaked GitLab issue email address lets anyone push code and run CI jobs as you

Security

Why Are US Water Treatment Plants Still Connected to the Internet?