
F5 has disclosed a critical zero-day vulnerability affecting BIG-IP Access Policy Manager (APM) that is already being exploited in the wild. Tracked as CVE-2026-94127, the flaw can allow an unauthenticated remote attacker to execute arbitrary code on vulnerable BIG-IP systems by sending specially crafted traffic to an affected OAuth configuration. The vulnerability is a heap-based […]
The post CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Exploited for Remote Code Execution appeared first on SOC Prime.