Find notable cyber news and cases, enriched with sources, timelines, and signals.

F5 BIG-IP APM zero-day RCE (CVE-2026-94127)

Vulnerability
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

A critical zero-day in F5 BIG-IP APM tracked as CVE-2026-94127 is being actively exploited for remote code execution on deployments configured as an OAuth Authorization Server. F5 released security updates and said systems using APM strictly as an OAuth Client / Resource Server are not affected. Administrators who cannot patch immediately can apply an iRule mitigation and should watch for multiple OAuth authentication failures, suspicious commands, and a TMM SIGABRT.

Related Happenings

PoisonedRefresh Linux rootkit on F5 BIG-IP APM

Malware Activity
H score31 First: 08.09.2026 23:08 Last: 08.09.2026 23:08 Sources 1

About this happening: The PoisonedRefresh malware activity targets F5 BIG-IP APM appliances and uses a fileless PHP web shell that Sophos said is injected into memory rather than writte...

F5 BIG-IP APM active exploitation wave (CVE-2025-53521)

Exploitation Wave
H score79 First: 02.04.2026 11:25 Last: 02.04.2026 11:25 Sources 1

About this happening: CVE-2025-53521 is being exploited against F5 BIG-IP APM systems, and F5 says new information in March 2026 changed the flaw from denial of service to remote...

CISA order to secure BIG-IP APM

Public Sector Action
H score89 First: 30.03.2026 13:59 Last: 30.03.2026 13:59 Sources 1

About this happening: CISA added CVE-2025-53521 to its actively exploited list and ordered federal agencies to secure BIG-IP APM systems by midnight on Monday, March 30, 2026, escal...

CISA KEV patch directive for CVE-2025-53521

Advisory/Mitigation
H score86 First: 30.03.2026 10:07 Last: 30.03.2026 10:07 Sources 1

About this happening: CISA added CVE-2025-53521 to its KEV catalog and told federal agencies to patch the F5 BIG-IP flaw within three days. The directive is urgent because the bug is be...

Ivanti EPMM exploitation wave (CVE-2026-1281)

Exploitation Wave
H score64 First: 12.02.2026 09:32 Last: 12.02.2026 09:32 Sources 1

About this happening: Ivanti Endpoint Manager Mobile (EPMM) is facing an active exploitation wave against CVE-2026-1281 and CVE-2026-1340, creating immediate risk for internet-facing ma...

Timeline

  1. 23.09.2026 10:17 2 articles · 0h ago

    F5 BIG-IP APM zero-day RCE (CVE-2026-94127)

    Initial Disclosure

    F5 disclosed that CVE-2026-94127 is a BIG-IP APM zero-day being exploited in remote code execution attacks on OAuth Authorization Server deployments. The company released security updates and a temporary iRule mitigation for systems that cannot be patched immediately.

    Show sources