F5 fixes actively exploited zero-day flaw in BIG-IP APM
Brief
Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch became available.
BIG-IP APM is a software component in F5’s BIG-IP hardware platform that enables companies to control access to internal network resources. APM performs various client-side checks and handles authorization and authentication, along with providing VPN connectivity for remote users.
The flaw, tracked as CVE-2026-94127, is described as a heap-based buffer overflow and is rated 9. 8 on the CVSS scale. The vulnerability impacts the BIG-IP system when configured in appliance mode as well but can be exploited only when both APM and an OAuth authorization server profile are configured.
