F5 releases security updates to address a critical zero-day vulnerability in BIG-IP Access Policy Manager (APM) that is being exploited for remote code execution (RCE) attacks. Multiple outlets report that the flaw allows attackers to execute code on affected BIG-IP systems, and that active exploitation is ongoing.
F5 says the vulnerability is tied to specific APM deployments. It affects only BIG-IP systems where APM functions as an OAuth authorization server that issues access tokens to applications. One outlet identifies the issue as CVE-2026-94127 and notes that F5 disclosed the problem in an advisory on September 22, followed by engineering hotfixes, with additional patches made available afterward. Coverage emphasizes the unauthenticated nature of the RCE path and the limited scope of affected configurations, rather than broader system-wide impact.
Overall, the reporting aligns on the vulnerability type (BIG-IP APM RCE), the fact that attackers are exploiting it, and the constrained conditions under which it applies (APM as an OAuth authorization server). Differences are mainly in how outlets describe timing and naming details.