F5 patches a BIG-IP APM zero-day exploited for unauthenticated code execution
On September 22, 2026, F5 disclosed CVE-2026-94127, a CVSS 9.8 flaw in the BIG-IP APM module being actively exploited against systems running as OAuth authorization servers. Apply the engineering hotfix or the iRule workaround, then hunt for repeated OAuth authentication failures.