F5 patches an exploited BIG-IP APM flaw affecting some OAuth server deployments
F5 says CVE-2026-94127 has been exploited in the wild. The issue is reported to affect a specific BIG-IP Access Policy Manager configuration, not every BIG-IP installation.
TLDR
F5 has issued an advisory for CVE-2026-94127, a critical BIG-IP Access Policy Manager vulnerability that it says has been exploited in the wild. Reporting says the exposure is tied to deployments using APM as an OAuth Authorization Server with both an access policy and OAuth profile on a virtual server. That configuration detail matters: organizations should identify whether they run it, consult F5’s advisory for affected releases and remediation, and treat the issue as an urgent security-maintenance task rather than assuming every BIG-IP system has the same exposure.
F5 patches an exploited BIG-IP APM flaw affecting some OAuth server deployments
F5 says CVE-2026-94127 has been exploited in the wild. The issue is reported to affect a specific BIG-IP Access Policy Manager configuration, not every BIG-IP installation.