An F5 zero-day with a Friday deadline
CVE-2026-94127 affects BIG-IP APM configured as an OAuth authorization server, is already being exploited, and CISA has ordered federal agencies to patch by Friday.
2 minEnterprise CyberSec
F5 has released updates for a critical zero-day in BIG-IP APM, its centralised access management proxy, after confirming the flaw is being exploited for remote code execution.
The vulnerability is tracked as CVE-2026-94127 and the affected configuration is specific: instances acting as an OAuth authorization server, where a BIG-IP APM access policy and an OAuth profile are both configured on a virtual server. Deployments using APM strictly as an OAuth client or resource server, without authorization server profiles, are not affected.
That distinction is worth reading carefully before concluding it does not apply. Access management proxies sit in front of everything else, which is why a flaw in one is worth more to an attacker than a flaw in what it protects.
F5 published indicators for defenders who need to check whether they were reached: multiple OAuth authentication failures combined with suspicious commands, followed shortly by a TMM process abort. For administrators who cannot patch immediately, the company supplied a mitigation in the form of an iRule applied to the affected virtual server.
On exposure, Shadowserver currently tracks more than 14,700 internet-facing addresses carrying BIG-IP APM fingerprints. There is no breakdown of how many are already patched or are honeypots, so the figure bounds the problem rather than describing it.
CISA added the flaw to its Known Exploited Vulnerabilities catalogue on Tuesday and ordered federal agencies to remediate by Friday. A three-day deadline is the agency's signal that it considers exploitation active and consequential rather than theoretical.
Retold from BleepingComputer. This is a summary in our own words; follow the link for the original reporting.