Act
active
F5 BIG-IP APM Zero-Day CVE-2026-94127 Actively Exploited for Unauth RCE
- Engineer — Act: CISA KEV-listed, public PoC, and confirmed active exploitation on F5 BIG-IP APM systems configured as OAuth authorization servers — apply F5’s engineering hotfix for CVE-2026-94127 immediately and verify whether any BIG-IP instances serve that OAuth role.
- SOC/IR — Act: Active exploitation of an edge device that precedes patching means assume-breach posture — sweep BIG-IP APM logs for anomalous unauthenticated requests to OAuth endpoints and hunt for post-compromise lateral movement since at least September 22.
- Leader — Act: Actively exploited unauthenticated RCE on a widely-deployed enterprise network appliance warrants same-week action — confirm whether BIG-IP APM is in use as an OAuth server, verify engineering has the hotfix on track, and be ready to brief leadership if it is.
- Signals: CVE-2026-94127 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.