F5 patches critical BIG-IP APM zero‑day flaw
🔒 F5 released fixes for a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) that was actively exploited in the wild. The heap-based buffer overflow, tracked as CVE-2026-94127 and rated 9.8, affects deployments configured as OAuth authorization servers and can also impact appliance-mode systems when both APM and an OAuth authorization server profile are enabled. F5 published hotfixes for the 21.x, 17.5.x and 17.1.x branches and provided an iRule mitigation while patches are applied.
