HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Zero-Day RCE in F5 BIG‑IP APM (CVE‑2026‑94127) Actively Exploited

F5 disclosed CVE‑2026‑94127, a remote‑code‑execution flaw in BIG‑IP APM when used as an OAuth Authorization Server, and confirmed it is being exploited in the wild. The incident underscores the need for continuous patch monitoring and auditable remediation to satisfy control‑assurance requirements.

Verisq™ Intelligence · 📅 September 23, 2026 · 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
bleepingcomputer.com

Critical Zero‑Day RCE in F5 BIG‑IP APM (CVE‑2026‑94127) Actively Exploited

What Happened – F5 disclosed a critical remote‑code‑execution (RCE) flaw (CVE‑2026‑94127) in BIG‑IP Access Policy Manager (APM) when the device is configured as an OAuth Authorization Server. The vulnerability is already being weaponised in the wild, prompting emergency patches and a CISA KEV directive.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous control‑monitoring of authentication‑service configurations and timely patch deployment – a core element of an ongoing control‑assurance program.
  • Provides concrete evidence (patch status, iRule mitigation, IOC logs) that can be collected and presented in audit trails to prove due‑diligence.
  • Highlights the importance of mapping this vulnerability to the “access control / secure configuration” control objective, which satisfies multiple frameworks simultaneously.

Who Is Affected – Enterprises that use F5 BIG‑IP APM for OAuth‑based access management, spanning finance, healthcare, cloud service providers, and any organization relying on F5 for application delivery.

Recommended Actions

  • Verify whether any BIG‑IP APM virtual servers are acting as OAuth Authorization Servers; if so, apply the emergency patch immediately.
  • Deploy the interim iRule mitigation where patching cannot be completed within the required window.
  • Conduct IOC hunting for multiple OAuth authentication failures followed by TMM SIGABRT events.
  • Record remediation steps in your control‑evidence repository to support audit readiness. Source: BleepingComputer

Technical Notes

  • Vulnerability: CVE‑2026‑94127, remote code execution via crafted OAuth requests on APM virtual servers configured as Authorization Servers.
  • Exploited in the wild; CISA added it to the KEV catalog and mandated federal remediation by Friday.
  • Mitigation: apply F5 security update or, if unavailable, install the supplied iRule. Source: same as above
📰 Original Source
https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →