SecurityF5 BIG-IP APM: Exploited OAuth RCE Hits Specific ConfigurationsCVE-2026-94127 enables unauthenticated RCE in APM systems with an access policy and OAuth authorisation-server profile.September 23, 2026·2 min read▲—▼