
F5 patches actively exploited BIG-IP zero-day, CISA gives federal agencies until Friday
CVE-2026-94127 lets attackers achieve remote code execution on BIG-IP APM instances configured as OAuth authorization servers. CISA added it to its Known Exploited Vulnerabilities catalog within a day of F5's advisory.










