F5 Fixes BIG-IP APM Zero-Day Enabling Unauthenticated RCE #BIGIPAPM #CISAKEV #CVE202694127

F5 Fixes BIG-IP APM Zero-Day Enabling Unauthenticated RCE #BIGIPAPM #CISAKEV #CVE202694127
F5 has patched a critical BIG-IP APM zero-day, CVE-2026-94127, exploited in remote code execution attacks on systems with OAuth authorization server settings enabled. #F5 #BIGIPAPM #CVE202694127
F5 and CISA say CVE-2026-94127, a critical BIG-IP APM flaw with CVSS 9.8, is being used as a zero-day for unauthenticated remote code execution. Hotfixes are available. #F5 #BIGIPAPM #CVE202694127
Sophos found F5 BIG-IP APM malware injecting a PHP web shell into memory, leaving disk files clean. Linked to CVE-2025-53521 and c05d5254, with indicators like apm_css.php3 and full_wt.php3. #F5 #BIGIPAPM #CVE202553521