CISA added CVE-2026-94127 (F5 BIG-IP APM) to its Known Exploited Vulnerabilities catalog on September 22, 2026, which means there is reliable evidence of exploitation in the wild. F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
Why it matters
CISA lists this as exploited in the wild. Unpatched BIG-IP and BIG-IP APM systems are exposed to active attacks now.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.
CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing…
Why it matters
CISA lists this as exploited in the wild. Unpatched BIG-IP and Multiple Products systems are exposed to active attacks now.