← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 23, 2026 · 20:44via CSO Online

F5 fixes actively exploited zero-day flaw in BIG-IP APM

Brief

Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch became available.

BIG-IP APM is a software component in F5’s BIG-IP hardware platform that enables companies to control access to internal network resources. APM performs various client-side checks and handles authorization and authentication, along with providing VPN connectivity for remote users.

The flaw, tracked as CVE-2026-94127, is described as a heap-based buffer overflow and is rated 9. 8 on the CVSS scale. The vulnerability impacts the BIG-IP system when configured in appliance mode as well but can be exploited only when both APM and an OAuth authorization server profile are configured.

Read more on CSO Online