CuraSec

Act active

F5 BIG-IP APM Zero-Day CVE-2026-94127 Actively Exploited for Unauth RCE

2026-09-23 15:27 UTC · The Hacker News · read the source ↗ #zero-day#rce#f5-big-ip
  • Engineer — Act: CISA KEV-listed, public PoC, and confirmed active exploitation on F5 BIG-IP APM systems configured as OAuth authorization servers — apply F5’s engineering hotfix for CVE-2026-94127 immediately and verify whether any BIG-IP instances serve that OAuth role.
  • SOC/IR — Act: Active exploitation of an edge device that precedes patching means assume-breach posture — sweep BIG-IP APM logs for anomalous unauthenticated requests to OAuth endpoints and hunt for post-compromise lateral movement since at least September 22.
  • Leader — Act: Actively exploited unauthenticated RCE on a widely-deployed enterprise network appliance warrants same-week action — confirm whether BIG-IP APM is in use as an OAuth server, verify engineering has the hotfix on track, and be ready to brief leadership if it is.
  • Signals: CVE-2026-94127 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.