Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
F5 and CISA on Tuesday warned organizations that threat actors have been exploiting a critical-severity BIG-IP Access Policy Manager (APM) vulnerability as a zero-day.
The flaw is exploitable via malicious traffic sent to the appliance when “a BIG-IP APM access policy and an OAuth profile are configured on a virtual server,” F5 notes in its advisory.
Tracked as CVE-2026-94127 (CVSS score of 9.8), the bug allows unauthenticated attackers to achieve remote code execution (RCE) on a vulnerable deployment.
“We have learned that this vulnerability has been exploited,” F5 says, noting that it discovered the security defect internally.
According to the company, the issue can be triggered only when BIG-IP APM is configured as an OAuth Authorization Server, not on deployments using APM as an OAuth Client/Resource Server.
“The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure,” the...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE