On September 22, 2026, F5 issued an advisory regarding a zero-day vulnerability that is actively being exploited in its BIG-IP Access Policy Manager (APM) product. This security flaw, identified as CVE-2026-94127, allows remote, unauthenticated attackers to execute code on APM appliances through malicious traffic under certain configurations. The vulnerability is rated as critical with a Common Vulnerability Scoring System (CVSS) score of 9.8 out of 10, underscoring the severe risk it poses to affected systems. F5 has confirmed that this vulnerability is already being exploited in the wild, making it imperative for organizations using BIG-IP APM to take immediate action to mitigate potential threats. The active exploitation of this flaw primarily targets exposed management interfaces, which are integral to maintaining secure access control and application access. Organizations relying on F5's BIG-IP APM should prioritize reviewing their systems to ensure they are not vulnerable to this exploit and monitor for any irregular activities that could signify an attempted breach. Implementing robust security measures and staying informed about the latest patches and advisories from F5 are crucial steps in safeguarding against potential attacks.