Critical Zero‑Day RCE in F5 BIG‑IP APM (CVE‑2026‑94127) Actively Exploited
What Happened – F5 disclosed a critical remote‑code‑execution (RCE) flaw (CVE‑2026‑94127) in BIG‑IP Access Policy Manager (APM) when the device is configured as an OAuth Authorization Server. The vulnerability is already being weaponised in the wild, prompting emergency patches and a CISA KEV directive.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous control‑monitoring of authentication‑service configurations and timely patch deployment – a core element of an ongoing control‑assurance program.
- Provides concrete evidence (patch status, iRule mitigation, IOC logs) that can be collected and presented in audit trails to prove due‑diligence.
- Highlights the importance of mapping this vulnerability to the “access control / secure configuration” control objective, which satisfies multiple frameworks simultaneously.
Who Is Affected – Enterprises that use F5 BIG‑IP APM for OAuth‑based access management, spanning finance, healthcare, cloud service providers, and any organization relying on F5 for application delivery.
Recommended Actions
- Verify whether any BIG‑IP APM virtual servers are acting as OAuth Authorization Servers; if so, apply the emergency patch immediately.
- Deploy the interim iRule mitigation where patching cannot be completed within the required window.
- Conduct IOC hunting for multiple OAuth authentication failures followed by TMM SIGABRT events.
- Record remediation steps in your control‑evidence repository to support audit readiness. Source: BleepingComputer
Technical Notes
- Vulnerability: CVE‑2026‑94127, remote code execution via crafted OAuth requests on APM virtual servers configured as Authorization Servers.
- Exploited in the wild; CISA added it to the KEV catalog and mandated federal remediation by Friday.
- Mitigation: apply F5 security update or, if unavailable, install the supplied iRule. Source: same as above