Critical Unauthenticated RCE in F5 BIG‑IP APM (CVE‑2026‑94127) Exploited on OAuth Authorization Servers
What It Is — A zero‑day vulnerability (CVE‑2026‑94127) in F5 BIG‑IP Access Policy Manager (APM) allows an unauthenticated attacker to execute arbitrary code on devices that are configured as OAuth authorization servers.
Exploitability — Publicly disclosed on 22 Sep 2026; evidence of active exploitation in the wild; CVSS v3.1 9.8 (Critical).
Affected Products — F5 BIG‑IP APM (any version acting as an OAuth token‑issuing endpoint).
Why It Matters for Trust & Control Assurance
- Continuous patch‑management evidence is a core control; missing it leaves a gap that spans SOC 2, ISO 27001, NIST CSF and many others.
- Demonstrable, time‑stamped remediation shows due‑diligence to auditors and enterprise buyers.
- Logging of OAuth token issuance and system‑level events provides the forensic trail needed for incident response and compliance reporting.
Recommended Actions
- Deploy the F5 engineering hotfix immediately on all APM instances serving OAuth.
- Verify the applied version against F5’s advisory and update your asset inventory.
- Enable and retain detailed logs for OAuth token requests and system calls; forward them to a SIEM.
- Document the patch process as control evidence in your governance platform.
- Conduct a rapid post‑patch validation scan to confirm remediation.
Source: The Hacker News – F5 patches critical BIG‑IP APM zero‑day