F5 fixes actively exploited zero-day flaw in BIG-IP APM
Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday.

Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday.
The short version
- The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch became available.
- BIG-IP APM is a software component in F5’s BIG-IP hardware platform that enables companies to control access to internal network resources.
- APM performs various client-side checks and handles authorization and authentication, along with providing VPN connectivity for remote users.
What happened
The flaw, tracked as CVE-2026-94127, is described as a heap-based buffer overflow and is rated 9.8 on the CVSS scale. The vulnerability impacts the BIG-IP system when configured in appliance mode as well but can be exploited only when both APM and an OAuth authorization server profile are configured.
Why it matters
Deployments using APM only as an OAuth client or resource server are not affected, F5 said in its advisory .
Summary by Nerd News Network. Read the full article at Network World via the links above and below.
