Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical ThreatIntel

Critical Unauthenticated RCE in F5 BIG‑IP APM (CVE‑2026‑94127) Exploited on OAuth Authorization Servers

F5 disclosed CVE‑2026‑94127, a zero‑day that lets attackers run code on BIG‑IP APM devices acting as OAuth servers. The flaw is being exploited in the wild, making timely patching essential for audit readiness and control assurance.

LiveThreat™ Intelligence · 📅 September 23, 2026· 📰 thehackernews.com
🔴
Severity
Critical
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
5 recommended
📰
Source
thehackernews.com

Critical Unauthenticated RCE in F5 BIG‑IP APM (CVE‑2026‑94127) Exploited on OAuth Authorization Servers

What It Is — A zero‑day vulnerability (CVE‑2026‑94127) in F5 BIG‑IP Access Policy Manager (APM) allows an unauthenticated attacker to execute arbitrary code on devices that are configured as OAuth authorization servers.

Exploitability — Publicly disclosed on 22 Sep 2026; evidence of active exploitation in the wild; CVSS v3.1 9.8 (Critical).

Affected Products — F5 BIG‑IP APM (any version acting as an OAuth token‑issuing endpoint).

Why It Matters for Trust & Control Assurance

  • Continuous patch‑management evidence is a core control; missing it leaves a gap that spans SOC 2, ISO 27001, NIST CSF and many others.
  • Demonstrable, time‑stamped remediation shows due‑diligence to auditors and enterprise buyers.
  • Logging of OAuth token issuance and system‑level events provides the forensic trail needed for incident response and compliance reporting.

Recommended Actions

  • Deploy the F5 engineering hotfix immediately on all APM instances serving OAuth.
  • Verify the applied version against F5’s advisory and update your asset inventory.
  • Enable and retain detailed logs for OAuth token requests and system calls; forward them to a SIEM.
  • Document the patch process as control evidence in your governance platform.
  • Conduct a rapid post‑patch validation scan to confirm remediation.

Source: The Hacker News – F5 patches critical BIG‑IP APM zero‑day

📰 Original Source
https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →