CVE-2026-94127: F5 BIG-IP APM RCE Under Active Exploitation F5 has released emergency engineering hotfixes for CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager (APM). The vulnerability allows an unauthenticated attacker to execute code when an APM access policy and an OAuth profile are configured on the same virtual server. F5 has confirmed exploitation in the wild.

Read the full article at SOCRadar →