ALEXKRI.NET
Resume Contact
← Back

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

If your BIG-IP APM is acting as an OAuth Authorization Server, today is a patching day. CVE-2026-94127 (CVSS 9.8) is unauthenticated RCE on the data plane, F5 found it internally, and it was already being exploited - CISA added it to KEV and gave federal agencies three days under BOD 26-04. Only the Authorization Server config is affected, so check your access policies before you panic-patch the fleet.

Read the source ↗