F5 has issued engineering hotfixes for CVE-2026-94127, a critical vulnerability in BIG-IP Access Policy Manager (APM) that has been exploited in the wild. The key scoping detail is configuration: the issue affects APM deployments acting as an OAuth authorization server with an access policy and OAuth profile on the same virtual server.
Why it matters
F5 rates the flaw 9.8 under CVSS v3.1. Crafted traffic to the affected virtual server can lead to unauthenticated remote code execution; restricting the management interface alone does not address the exposed path. CISA added the issue to its Known Exploited Vulnerabilities catalog.
What defenders should do
- Identify BIG-IP systems where APM is configured as an OAuth authorization server.
- Apply F5’s engineering hotfix for the affected release branch, or obtain the vendor’s temporary mitigation where patching cannot happen immediately.
- Preserve evidence and review APM and audit logs for repeated failed UserInfo requests, suspicious commands, and related TMM failures.
Organizations should validate exposure based on the authorization-server role rather than assuming every OAuth-related APM deployment is affected.
Source: The Hacker News: F5 BIG-IP APM zero-day; linked F5, CISA, CVE, and CERT-EU advisories.
